LatentBot
- First seen
- 2013-06-01 00:00:00
- Malware type
- botnet, wiper, dropper
- Family
- Malware family
- Last IoC activity
- 2026-07-19 13:45:03
- Profile updated
- 2026-07-07 15:09:16
Targeted industries: financial-services professional-services
Targeted regions: country_code:us country_code:gb country_code:kr country_code:br country_code:ae country_code:sg country_code:ca country_code:pe country_code:pl
Context
FireEye describes this malware as a highly obfuscated bot that has been in the wild since mid-2013. It has managed to leave hardly any traces on the Internet, is capable of watching its victims without ever being noticed, and can even corrupt a hard disk, thus making a PC useless. Using Dynamic Threat Intelligence, they have observed multiple campaigns targeting multiple industries in the United States, United Kingdom, South Korea, Brazil, United Arab Emirates, Singapore, Canada, Peru and Poland – primarily in the financial services and insurance sectors. Although the infection strategy is not new, the final payload dropped – which they named LATENTBOT – caught attention since it implements several layers of obfuscation, a unique exfiltration mechanism, and has been very successful at infecting multiple organizations.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Latentbot_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Latentbot (report)
- malware-traffic-analysis.net — Index (report)
- Mandiant — Latentbot Trace Me (report)
- blog.malwarebytes.com — Latentbot (report)
- cys-centrum.com — Module Trojan For Unauthorized Access (report)
- cert.pl — Latentbot Modularny I Silnie Zaciemniony Bot (report)