New Latrodectus malware replaces IcedID in network breaches
ID: fab3f690-1dc8-5ef9-b87f-98fb4d52bf53
STIX ID: report--fab3f690-1dc8-5ef9-b87f-98fb4d52bf53
Feed Name: Bleeping Computer
Latrodectus is a newly observed malware loader likely evolved from the IcedID family and seen in phishing campaigns since November 2023, with increased activity in Feb–Mar 2024. Operators (linked to TA577/TA578) use fake copyright complaints submitted via website contact forms that direct victims to a Firebase-hosted JavaScript which executes MSI installers from a WebDAV share to deploy a DLL payload; the malware performs multiple sandbox/evasion checks and functions as a downloader capable of retrieving and executing further payloads under C2 control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
