LatentBot

First seen
2013-06-01 00:00:00
Malware type
botnet, wiper, dropper
Family
Malware family
Last IoC activity
2026-07-19 13:45:03
Profile updated
2026-07-07 15:09:16

Targeted industries: financial-services professional-services

Targeted regions: country_code:us country_code:gb country_code:kr country_code:br country_code:ae country_code:sg country_code:ca country_code:pe country_code:pl

Context

FireEye describes this malware as a highly obfuscated bot that has been in the wild since mid-2013. It has managed to leave hardly any traces on the Internet, is capable of watching its victims without ever being noticed, and can even corrupt a hard disk, thus making a PC useless. Using Dynamic Threat Intelligence, they have observed multiple campaigns targeting multiple industries in the United States, United Kingdom, South Korea, Brazil, United Arab Emirates, Singapore, Canada, Peru and Poland – primarily in the financial services and insurance sectors. Although the infection strategy is not new, the final payload dropped – which they named LATENTBOT – caught attention since it implements several layers of obfuscation, a unique exfiltration mechanism, and has been very successful at infecting multiple organizations.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Latentbot_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Latentbot (report)
  • malware-traffic-analysis.net — Index (report)
  • Mandiant — Latentbot Trace Me (report)
  • blog.malwarebytes.com — Latentbot (report)
  • cys-centrum.com — Module Trojan For Unauthorized Access (report)
  • cert.pl — Latentbot Modularny I Silnie Zaciemniony Bot (report)

External references