logo

New Latrodectus malware replaces IcedID in network breaches

ID: fab3f690-1dc8-5ef9-b87f-98fb4d52bf53

STIX ID: report--fab3f690-1dc8-5ef9-b87f-98fb4d52bf53

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-04-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Latrodectus is a newly observed malware loader likely evolved from the IcedID family and seen in phishing campaigns since November 2023, with increased activity in Feb–Mar 2024. Operators (linked to TA577/TA578) use fake copyright complaints submitted via website contact forms that direct victims to a Firebase-hosted JavaScript which executes MSI installers from a WebDAV share to deploy a DLL payload; the malware performs multiple sandbox/evasion checks and functions as a downloader capable of retrieving and executing further payloads under C2 control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.