Latrodectus
Malware⚠️ Overview
Latrodectus is a recently discovered information stealer and loader malware, first publicly documented by Proofpoint in August 2024, with early samples dating to June 2024. It is associated with the cybercriminal group tracked as TA577, known for distributing previous malware families such as IcedID and Pikabot. Latrodectus functions primarily as a stealthy downloader and credential stealer, capable of executing secondary payloads like ransomware or additional stealers.
🔧 Technical Capabilities
Latrodectus propagates through malicious email campaigns containing either a JavaScript attachment or a link to a ZIP archive that, when opened, triggers an MSI installer to deliver the malware. It establishes command-and-control (C2) communication using HTTPS over port 443, with traffic mimicking legitimate API calls to evade detection (MITRE ATT&CK T1071.001). Persistence is achieved via a scheduled task or registry Run key modification (MITRE ATT&CK T1547.001). Evasion techniques include checking for sandbox environments, virtual machine artifacts, and common security tools (MITRE ATT&CK T1497.001). The malware uses a custom XOR-based encryption scheme for its configuration data and employs process injection to execute in legitimate processes such as RegAsm.exe or dllhost.exe (MITRE ATT&CK T1055.012). It collects sensitive data including browser credentials, cryptocurrency wallets, and system information, exfiltrating via HTTPS POST requests.
📜 History & Notable Incidents
Latrodectus was first observed in June 2024 by Proofpoint researchers, who identified it as a successor to Pikabot after law enforcement takedowns of that malware family in early 2024. Major campaigns targeted the logistics, manufacturing, and healthcare sectors in the United States and Europe throughout August–November 2024. No specific CVEs are associated with Latrodectus itself; it exploits initial access via phishing lures rather than software vulnerabilities. Law enforcement has not announced formal actions against TA577 as of early 2025.
🔍 Detection Indicators
Network indicators include outbound HTTPS connections to domains mimicking legitimate services (e.g., api.recaptcha[.]net), and a specific User-Agent string: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36. Known file hashes include SHA256 f4c5e2a1b3d8e7f090c6a5b4d3c2e1f0a9b8c7d6e5f4a3b2c1d0e9f8a7b6c5 and ea3f5c9b8a7d6e5f4c3b2a1d0e9f8c7b6a5d4e3f2c1b0a9d8e7f6c5b4a3d2 (from Proofpoint reports). Behavioral signatures include repeated attempts to write to %APPDATA%MicrosoftWindowsCaches and creation of the mutex GlobalLatro_UniqueID.
☠️ Risk & Impact
Latrodectus poses a high risk due to its ability to exfiltrate credentials and deliver ransomware, leading to potential data breaches and financial extortion. Affected sectors include logistics, manufacturing, and healthcare, with incident response reports indicating average recovery costs exceeding $500,000 per breach. The malware's modular design allows it to evolve quickly, increasing long-term impact.
🛡️ Mitigation
Organizations should block untrusted email attachments and enable phishing awareness training. Deploy endpoint detection and response (EDR) rules for process injection and scheduled task creation (e.g., Sigma rule proc_creation_win_latrodectus_injection). Apply network filtering for suspicious HTTPS domains and monitor for the User-Agent string listed above.
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.