logo

Latrodectus malware and how to defend against it with Wazuh

ID: 976d9746-57f0-5158-9f1f-3edcb0f1085b

STIX ID: report--976d9746-57f0-5158-9f1f-3edcb0f1085b

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-12-05

Date Updated: 2026-03-27

Author: Sponsored by Wazuh

...
...

Latrodectus is a modular, fileless Windows malware family observed in campaigns since late 2023 that uses dynamic API resolution, string obfuscation, persistence via scheduled tasks, environment and VM checks, mutexes, and encrypted HTTPS C2 to perform selective data exfiltration and to download additional modules (including ransomware). The report details tactics and techniques, links activity to TA577/TA578, and provides mitigation guidance such as phishing training, endpoint detection, network segmentation, backups, and patching, plus how Wazuh can detect related behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.