Latrodectus Malware Loader Emerges as IcedID's Successor in Phishing Campaigns
ID: d2611f2d-b617-5cec-9e14-fb4362b40d6f
STIX ID: report--d2611f2d-b617-5cec-9e14-fb4362b40d6f
Feed Name: The Hacker News
Researchers observed a March–May 2024 surge in phishing campaigns delivering a new loader named Latrodectus—likely a successor to IcedID—alongside multiple malware families (DarkGate, D3F@ck Loader, Raccoon Stealer, DanaBot, Remcos) and upgraded phishing-as-a-service tooling (Tycoon) that harvests session cookies and evades MFA; the report describes infection chains (malicious JavaScript, WMI/msiexec-installation of remote MSIs, JAR->PowerShell->AutoIT), persistence mechanisms, C2 over HTTPS, enumeration and self-deletion features, and widespread use of obfuscation and sandbox-evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
