Latrodectus
MITRE ATT&CK: S1160 View on attack.mitre.org
Aliases: IceNova, Unidentified 111, BLACKWIDOW, Latrodectus, Lotus
- First seen
- 2023-01-01 00:00:00
- Malware type
- downloader, loader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 904 (577 malicious)
- Last IoC activity
- 2026-09-02 03:16:02
- Profile updated
- 2026-07-07 13:15:39
Targeted industries: financial-services technology-and-telecommunications government-and-public-sector
Targeted regions: country_code:us country_code:gb country_code:au
Context
Latrodectus is a Windows malware downloader that has been used since at least 2023 to download and execute additional payloads and modules. Latrodectus has most often been distributed through email campaigns, primarily by TA577 and TA578, and has infrastructure overlaps with historic IcedID operations.
Recent IoC activity
579 malicious indicators in Maltiverse are attributed to Latrodectus (S1160). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | luatdaiviet.vn | 2026-09-03 | 1 |
| hostname | eqx.com.br | 2026-09-03 | 1 |
| hostname | farrdigital.com | 2026-09-03 | 1 |
| hostname | bewsertinekk.info | 2026-09-03 | 2 |
| hostname | englishtoday.com.my | 2026-09-03 | 1 |
| hostname | xiolewarentiom.com | 2026-09-03 | 1 |
| hostname | legalbriefgenerator.com | 2026-09-03 | 1 |
| hostname | rolefenik.com | 2026-09-03 | 1 |
| hostname | digitalcftv.com.br | 2026-09-03 | 1 |
| hostname | mrflowsticoertomy.com | 2026-09-03 | 1 |
| hostname | filojaspergloplas.com | 2026-09-03 | 1 |
| hostname | opewolumeras.com | 2026-09-03 | 1 |
| hostname | uxizfixcomplandrush.com | 2026-09-03 | 1 |
| hostname | registeredagentsingeorgia.com | 2026-09-02 | 1 |
| hostname | topguningit.com | 2026-09-02 | 2 |
| URL | https://kiprihorycom.com/work/ | 2026-09-02 | 1 |
| IP address | 178.16.52.248 | 2026-09-02 | 3 |
| hostname | lumaya.cl | 2026-09-02 | 1 |
| hostname | gladirustoklioasfar.com | 2026-09-02 | 1 |
| hostname | studio-minx.com | 2026-09-02 | 1 |
Detection coverage
- 10 YARA rules
- 632 Sigma rules
Malware & tools used
- Web Service (attack-pattern)
- Rundll32 (attack-pattern)
- Standard Encoding (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Msiexec (attack-pattern)
- Network Share Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Scheduled Task (attack-pattern)
- Malicious Link (attack-pattern)
- Dynamic API Resolution (attack-pattern)
- Data from Local System (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- File Deletion (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Component Object Model (attack-pattern)
- Software Packing (attack-pattern)
- JavaScript (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Web Protocols (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Native API (attack-pattern)
Used by threat actors
Detection rules
- SEKOIA_Latrodectus_Exports (yara-rule)
- SEKOIA_Loader_Latrodectus_Dll (yara-rule)
- SEKOIA_Latrodectus_Br4_Js_Dropper (yara-rule)
- SIGNATURE_BASE_MAL_Chrysalis_Dllloader_Feb26 (yara-rule)
- SIGNATURE_BASE_MAL_Chrysalis_Shellcode_Loader_Feb26 (yara-rule)
- SIGNATURE_BASE_MAL_Chrysalis_Backdoor_Feb26 (yara-rule)
- CAPE_Latrodectus (yara-rule)
- CAPE_Latrodectus_1 (yara-rule)
- CAPE_Latrodectus_AES (yara-rule)
- MALPEDIA_Win_Latrodectus_Auto (yara-rule)
Reports & references
- Microsoft — Threat Actors Leverage Tax Season To Deploy Tax Themed Phishing Campaigns (report)
- proofpoint.com — Latrodectus Spider Bytes Ice (report)
- bitsight.com — Latrodectus Are You Coming Back (report)
- spamhaus.org — Botnet Threat Update January To June 2025 (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- spamhaus.org — Botnet Threat Update July To December 2025 (report)
- trustwave.com — Pronsis Loader A Jphp Driven Malware Diverging From D3Fck Loader (report)
- cyble.com — Double Trouble Latrodectus And Acr Stealer Observed Spreading Via Google Authenticator Phishing Site (report)
- proofpoint.com — Security Brief Clickfix Social Engineering Technique Floods Threat Landscape (report)
- blog.eclecticiq.com — Inside Intelligence Center Lunar Spider Enabling Ransomware Attacks On Financial Sector With Brute Ratel C4 And Latrodectus (report)
- blog.krakz.fr — Latrodectus (report)
- blog.reveng.ai — Latrodectus Distribution Via Brc4 (report)
- thedfirreport.com — From A Single Click How Lunar Spider Enabled A Near Two Month Intrusion (report)
- securonix.com — Securonix Threat Research Security Advisory Frozenshadow Attack Campaign (report)
- esentire.com — Danabots Latest Move Deploying Icedid (report)
- elastic.co — Spring Cleaning With Latrodectus (report)
- netresec.com (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Latrodectus (report)
- cert.pl — Fake Captcha In Action (report)
- github.com — Latrodectus Static Unpacker.Py (report)
- vmray.com — Latrodectus A Year In The Making (report)
- research.openanalysis.net — Latrodectus (report)
- x.com — 1792826263738208343 (report)
- medium.com — Icedid Gets Loaded Af073B7B6D39 (report)
- medium.com — Inside Latrodectus A Dive Into Malware Tactics And Mitigation 5629Cdb109Ea (report)
External references
- mitre-attack — S1160
- IceNova
- Unidentified 111
- Bleeping Computer Latrodectus April 2024
- Bitsight Latrodectus June 2024
- Latrodectus APR 2024
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy