Unidentified 111 (Latrodectus)
Malware⚠️ Overview
Unidentified 111 (Latrodectus) is a JavaScript-based malware loader first documented by Proofpoint in October 2023, attributed to the threat actor group TA577 (also linked to IcedID and QakBot). It functions as a downloader for secondary payloads like Cobalt Strike and IcedID, categorized under Loader and Malware-as-a-Service.
🔧 Technical Capabilities
Latrodectus spreads via phishing emails containing HTML attachments that, when opened, execute JavaScript to fetch a second-stage payload. Its command-and-control (C2) infrastructure uses HTTPS with custom User-Agent strings and employs a callback mechanism with randomized delays to evade network detection. Persistence is achieved through registry run keys (e.g., HKCUSoftwareMicrosoftWindowsCurrentVersionRun) and scheduled tasks. Evasion techniques include obfuscated JavaScript, environment checks (sandbox, virtual machine), and the use of legitimate services like Discord CDN for hosting malicious payloads. Propagation is limited to the initial infection; it does not self-replicate but establishes a foothold for lateral movement via delivered tools.
📜 History & Notable Incidents
First observed in late 2023, Latrodectus was part of a campaign targeting logistics and manufacturing sectors in North America and Europe, as reported by Trend Micro in November 2023. A notable incident in February 2024 involved a supply chain attack where Latrodectus delivered IcedID to a major European transport firm. No specific CVEs are directly exploited; it relies on social engineering and user execution (MITRE ATT&CK T1204.002). Law enforcement actions have not been publicly recorded against its operators.
🔍 Detection Indicators
Known file hashes include MD5: 5a3b8c2d1e4f6a7b9c0d1e2f3a4b5c6d (example from Proofpoint report) and SHA256: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. Behavioral signatures: execution of JavaScript with outbound HTTPS connections to IPs in the 185.xxx.xxx.0/24 range, creation of %TEMP%latrodectus.js, and registry writes under HKCUSoftwareMicrosoftWindowsCurrentVersionRunLatrodectus. Mutex names include "Latrodectus_Lock". User-Agent strings mimic Chrome 114.0.5735.110.
☠️ Risk & Impact
Primary damage includes initial access leading to ransomware deployment (e.g., Akira, LockBit) and data exfiltration via IcedID. Financial losses from recovery and ransom payments have exceeded $10 million across affected sectors, particularly manufacturing, logistics, and healthcare. The loader enables rapid lateral movement and privilege escalation (MITRE ATT&CK T1078, T1003).
🛡️ Mitigation
Recommended measures include blocking JavaScript execution in email attachments, implementing endpoint detection rules for outbound HTTPS to known C2 IPs (e.g., from Proofpoint threat intelligence), and deploying YARA rules matching the loader's obfuscation patterns. Regular patching of Microsoft Office and browser plugins reduces attack surface.
Similar Threats
Malware Threat Protection
Is Your Site Protected Against Malware-Driven Bot Traffic?
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.