logo

Latrodectus Malware Loader Emerges as IcedID's Successor in Phishing Campaigns

ID: d2611f2d-b617-5cec-9e14-fb4362b40d6f

STIX ID: report--d2611f2d-b617-5cec-9e14-fb4362b40d6f

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-05-20

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Researchers observed a March–May 2024 surge in phishing campaigns delivering a new loader named Latrodectus—likely a successor to IcedID—alongside multiple malware families (DarkGate, D3F@ck Loader, Raccoon Stealer, DanaBot, Remcos) and upgraded phishing-as-a-service tooling (Tycoon) that harvests session cookies and evades MFA; the report describes infection chains (malicious JavaScript, WMI/msiexec-installation of remote MSIs, JAR->PowerShell->AutoIT), persistence mechanisms, C2 over HTTPS, enumeration and self-deletion features, and widespread use of obfuscation and sandbox-evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.