Latrodectus

MITRE ATT&CK: S1160 View on attack.mitre.org

Aliases: IceNova, Unidentified 111, BLACKWIDOW, Latrodectus, Lotus

First seen
2023-01-01 00:00:00
Malware type
downloader, loader
Family
Malware family
Operating systems
windows
Related IoCs
904 (577 malicious)
Last IoC activity
2026-09-02 03:16:02
Profile updated
2026-07-07 13:15:39

Targeted industries: financial-services technology-and-telecommunications government-and-public-sector

Targeted regions: country_code:us country_code:gb country_code:au

Context

Latrodectus is a Windows malware downloader that has been used since at least 2023 to download and execute additional payloads and modules. Latrodectus has most often been distributed through email campaigns, primarily by TA577 and TA578, and has infrastructure overlaps with historic IcedID operations.

Recent IoC activity

579 malicious indicators in Maltiverse are attributed to Latrodectus (S1160). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname luatdaiviet.vn 2026-09-03 1
hostname eqx.com.br 2026-09-03 1
hostname farrdigital.com 2026-09-03 1
hostname bewsertinekk.info 2026-09-03 2
hostname englishtoday.com.my 2026-09-03 1
hostname xiolewarentiom.com 2026-09-03 1
hostname legalbriefgenerator.com 2026-09-03 1
hostname rolefenik.com 2026-09-03 1
hostname digitalcftv.com.br 2026-09-03 1
hostname mrflowsticoertomy.com 2026-09-03 1
hostname filojaspergloplas.com 2026-09-03 1
hostname opewolumeras.com 2026-09-03 1
hostname uxizfixcomplandrush.com 2026-09-03 1
hostname registeredagentsingeorgia.com 2026-09-02 1
hostname topguningit.com 2026-09-02 2
URL https://kiprihorycom.com/work/ 2026-09-02 1
IP address 178.16.52.248 2026-09-02 3
hostname lumaya.cl 2026-09-02 1
hostname gladirustoklioasfar.com 2026-09-02 1
hostname studio-minx.com 2026-09-02 1

Detection coverage

  • 10 YARA rules
  • 632 Sigma rules

Malware & tools used

  • Web Service (attack-pattern)
  • Rundll32 (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Msiexec (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Malicious Link (attack-pattern)
  • Dynamic API Resolution (attack-pattern)
  • Data from Local System (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • File Deletion (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Component Object Model (attack-pattern)
  • Software Packing (attack-pattern)
  • JavaScript (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Web Protocols (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Native API (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Latrodectus_Exports (yara-rule)
  • SEKOIA_Loader_Latrodectus_Dll (yara-rule)
  • SEKOIA_Latrodectus_Br4_Js_Dropper (yara-rule)
  • SIGNATURE_BASE_MAL_Chrysalis_Dllloader_Feb26 (yara-rule)
  • SIGNATURE_BASE_MAL_Chrysalis_Shellcode_Loader_Feb26 (yara-rule)
  • SIGNATURE_BASE_MAL_Chrysalis_Backdoor_Feb26 (yara-rule)
  • CAPE_Latrodectus (yara-rule)
  • CAPE_Latrodectus_1 (yara-rule)
  • CAPE_Latrodectus_AES (yara-rule)
  • MALPEDIA_Win_Latrodectus_Auto (yara-rule)

Reports & references

  • Microsoft — Threat Actors Leverage Tax Season To Deploy Tax Themed Phishing Campaigns (report)
  • proofpoint.com — Latrodectus Spider Bytes Ice (report)
  • bitsight.com — Latrodectus Are You Coming Back (report)
  • spamhaus.org — Botnet Threat Update January To June 2025 (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • spamhaus.org — Botnet Threat Update July To December 2025 (report)
  • trustwave.com — Pronsis Loader A Jphp Driven Malware Diverging From D3Fck Loader (report)
  • cyble.com — Double Trouble Latrodectus And Acr Stealer Observed Spreading Via Google Authenticator Phishing Site (report)
  • proofpoint.com — Security Brief Clickfix Social Engineering Technique Floods Threat Landscape (report)
  • blog.eclecticiq.com — Inside Intelligence Center Lunar Spider Enabling Ransomware Attacks On Financial Sector With Brute Ratel C4 And Latrodectus (report)
  • blog.krakz.fr — Latrodectus (report)
  • blog.reveng.ai — Latrodectus Distribution Via Brc4 (report)
  • thedfirreport.com — From A Single Click How Lunar Spider Enabled A Near Two Month Intrusion (report)
  • securonix.com — Securonix Threat Research Security Advisory Frozenshadow Attack Campaign (report)
  • esentire.com — Danabots Latest Move Deploying Icedid (report)
  • elastic.co — Spring Cleaning With Latrodectus (report)
  • netresec.com (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Latrodectus (report)
  • cert.pl — Fake Captcha In Action (report)
  • github.com — Latrodectus Static Unpacker.Py (report)
  • vmray.com — Latrodectus A Year In The Making (report)
  • research.openanalysis.net — Latrodectus (report)
  • x.com — 1792826263738208343 (report)
  • medium.com — Icedid Gets Loaded Af073B7B6D39 (report)
  • medium.com — Inside Latrodectus A Dive Into Malware Tactics And Mitigation 5629Cdb109Ea (report)

External references