New Latrodectus malware attacks use Microsoft, Cloudflare themes
ID: 785df819-4de5-5da6-b25f-bc42080166b6
STIX ID: report--785df819-4de5-5da6-b25f-bc42080166b6
Feed Name: Bleeping Computer
Latrodectus (aka Unidentified 111 / IceNova) is being distributed via reply-chain phishing that uses PDF attachments and fake Cloudflare captchas to trick users into downloading an obfuscated JavaScript which fetches an MSI; the MSI installs a DLL in %AppData% that is launched via rundll32 and functions as a downloader/backdoor. Researchers link the campaign to IcedID developers and have observed it dropping Lumma and Danabot, presenting a significant risk of credential theft and subsequent malware escalation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
