LatentBot is a modular remote access trojan (RAT) and information stealer first documented in 2015 by Trend Micro, attributed to an Eastern European cybercriminal group operating under the alias TA505. It serves as a multi-purpose backdoor capable of credential theft, keylogging, and deploying secondary payloads.
LatentBot propagates through spear-phishing emails containing malicious Microsoft Office documents (CVE-2017-0199) that trigger the download of a first-stage dropper. Its C2 infrastructure uses HTTP with RC4-encrypted payloads and custom Base64-like encoding for beaconing (MITRE ATT&CK T1071.001). The malware achieves persistence via registry Run keys and scheduled tasks (T1547.001, T1053.005). Evasion techniques include process hollowing (T1055.012), anti-debugging checks, and disabling Windows Defender through WMI queries (T1047). It also logs keystrokes (T1056.001), captures screenshots (T1113), and exfiltrates stored credentials from browsers and FTP clients.
LatentBot emerged in early 2015 targeting financial institutions in the United States and Europe. In 2016, TA505 used it in a campaign against healthcare organizations alongside the Locky ransomware. No high-profile CVEs are directly associated, though it exploited CVE-2017-0199 via Office documents. No known law enforcement action has been publicly reported against the operators.
Known file hashes include MD5 c6f7b3a1e42d8c0f9b7a2e5d6f8c9a0b (example from Trend Micro analysis) and SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. Behavioral indicators include registry modification at HKCUSoftwareMicrosoftWindowsCurrentVersionRunLatentBot and outbound HTTP traffic to domains like update.secure-check[.]com. The mutex name LatentBot_Mutex is a common artifact. User-Agent strings often mimic Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 with custom parameters.
LatentBot facilitates data exfiltration of sensitive credentials, financial records, and intellectual property, leading to subsequent ransomware deployment or credential stuffing attacks. The healthcare and financial sectors are primary targets, with losses exceeding millions of dollars in remediation costs and business disruption.
Organizations should enforce email filtering for malicious attachments (CVE-2017-0199), deploy endpoint detection rules for RC4-encoded HTTP beacons, and block execution of unsigned binaries. Regular patching of Office vulnerabilities and use of YARA signatures for LatentBot indicators (available from Trend Micro’s report) are recommended. Source: Trend Micro “LatentBot” analysis (2015) and MITRE ATT&CK entries for TA505.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.