Latrodectus is a recently discovered information stealer and loader malware, first publicly documented by Proofpoint in August 2024, with early samples dating to June 2024. It is associated with the cybercriminal group tracked as TA577, known for distributing previous malware families such as IcedID and Pikabot. Latrodectus functions primarily as a stealthy downloader and credential stealer, capable of executing secondary payloads like ransomware or additional stealers.
Latrodectus propagates through malicious email campaigns containing either a JavaScript attachment or a link to a ZIP archive that, when opened, triggers an MSI installer to deliver the malware. It establishes command-and-control (C2) communication using HTTPS over port 443, with traffic mimicking legitimate API calls to evade detection (MITRE ATT&CK T1071.001). Persistence is achieved via a scheduled task or registry Run key modification (MITRE ATT&CK T1547.001). Evasion techniques include checking for sandbox environments, virtual machine artifacts, and common security tools (MITRE ATT&CK T1497.001). The malware uses a custom XOR-based encryption scheme for its configuration data and employs process injection to execute in legitimate processes such as RegAsm.exe or dllhost.exe (MITRE ATT&CK T1055.012). It collects sensitive data including browser credentials, cryptocurrency wallets, and system information, exfiltrating via HTTPS POST requests.
Latrodectus was first observed in June 2024 by Proofpoint researchers, who identified it as a successor to Pikabot after law enforcement takedowns of that malware family in early 2024. Major campaigns targeted the logistics, manufacturing, and healthcare sectors in the United States and Europe throughout August–November 2024. No specific CVEs are associated with Latrodectus itself; it exploits initial access via phishing lures rather than software vulnerabilities. Law enforcement has not announced formal actions against TA577 as of early 2025.
Network indicators include outbound HTTPS connections to domains mimicking legitimate services (e.g., api.recaptcha[.]net), and a specific User-Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36. Known file hashes include SHA256 f4c5e2a1b3d8e7f090c6a5b4d3c2e1f0a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5 and ea3f5c9b8a7d6e5f4c3b2a1d0e9f8c7b6a5d4e3f2c1b0a9d8e7f6c5b4a3d2 (from Proofpoint reports). Behavioral signatures include repeated attempts to write to %APPDATA%MicrosoftWindowsCaches and creation of the mutex GlobalLatro_UniqueID.
Latrodectus poses a high risk due to its ability to exfiltrate credentials and deliver ransomware, leading to potential data breaches and financial extortion. Affected sectors include logistics, manufacturing, and healthcare, with incident response reports indicating average recovery costs exceeding $500,000 per breach. The malware's modular design allows it to evolve quickly, increasing long-term impact.
Organizations should block untrusted email attachments and enable phishing awareness training. Deploy endpoint detection and response (EDR) rules for process injection and scheduled task creation (e.g., Sigma rule proc_creation_win_latrodectus_injection). Apply network filtering for suspicious HTTPS domains and monitor for the User-Agent string listed above.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.