Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Latrodectus

170
Global rank
139 infographic chevron month
Month rank
157 infographic chevron week
Week rank
0
IOCs

Latrodectus is a malicious loader that is used by threat actors to gain a foothold on compromised devices and deploy additional malware. It has been associated with the IcedID trojan and has been used by APT groups in targeted attacks. The malware can gather system information, launch executables, and detect sandbox environments. It uses encryption and obfuscation to evade detection and can establish persistence on the infected device.

Loader
Type
Unknown
Origin
1 August, 2023
First seen
11 August, 2026
Last seen
Also known as
Unidentified 111
BLACKWIDOW
IceNova

How to analyze Latrodectus with ANY.RUN

Type
Unknown
Origin
1 August, 2023
First seen
11 August, 2026
Last seen

IOCs

IP addresses
2.16.204.145
48.209.138.189
48.209.138.168
172.64.154.167
48.192.1.64
2.16.204.135
40.126.32.133
23.52.181.141
172.211.123.250
162.159.36.2
74.178.240.51
74.178.76.128
88.221.92.192
48.192.1.65
88.221.169.205
48.209.6.48
40.126.32.68
2.16.241.218
2.16.241.201
172.211.123.248
Hashes
ec29ce8537e112869dfccb8a57574ebd01eecd7ff5c9fff54fdc1b05ea8941b3
62a2cb5aa12f592f3994d8e7a6483ae549b10df8f7c8064a91e9ccb7a2d53bdb
77bf693b39878fdfe8dae97ae541b54ebe3179ea4a98225713908eb1f49a4158
e728f79439e07df1afbcf03e8788fa0b8b08cf459db31fc8568bc511bf799537
88dd7ee9fa22ecdbdc6b3d47db83bc3d72360aeb43588e6a9a008b224389cb1c
4f92e804a11453382ebff7fb0958879bae88fe3366306911dec9d811cd306eed
719e644c31d0cc6b891f6a1253655dfba39a3b78e06d24817be1d8492b172b48
7f0121322785c107bfdfe343e49f06c604c719baff849d07b6e099675d173961
3c081097dca98557b27c1949496cedc94f1b8f6a952d6b106e312e0239bc5b21
36d9bab35d1e4b50045bf902f5d42b6f865488c75f6e60fc00a6cd6f69034ab0
426e6cf199a8268e8a7763ec3a4dd7add982b28c51d89ebea90ca792cbae14dd
1e0e63b446eecf6c9781c7d1cae1f46a3bb31654a70612f71f31538fb4f4729a
f858747a92e6df6939c270eda54d6d6ea9bf5da3952e8c57d3ced96754aa72eb
bcccae1d91009180f4b87f7f3551ec2c13d40cbe01babcc0b037cd9ba36ed01d
e4f60d0aa6d7f3d3b6a6494b1c861b99f649c6f9ec51abaf201b20f297327c95
2a6bb3bc75e9377414701bcf5887dd4e1b59803d717c9f7ff57100c5eeba3ef7
bb0885d1f6f81f14d725c099f4cc49560d25ecb40cc9e7286710c3cb20790ef3
8ab5f5bceba02a4b4e73a1997018a96c5345c24a9ff389db36f9e84b4b59d7f2
2870203e1312b73dbac691d704409e0255a65c054921289117c5167486656a6e
daec39fd5a319cfe3f660c9065e52292e6cd6ff732135bcd05cbbd6508cfcffc
Domains
google.com
th.bing.com
www.bing.com
settings-win.data.microsoft.com
activation-v2.sls.microsoft.com
fe3cr.delivery.mp.microsoft.com
slscr.update.microsoft.com
client.wns.windows.com
login.live.com
go.microsoft.com
www.microsoft.com
ocsp.digicert.com
self.events.data.microsoft.com
oneocsp.microsoft.com
crl.microsoft.com
URLs
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
https://th.bing.com/th?id=odswg.1e1da29b-91ea-4d2e-ac12-df81dfa2c53d&w=124&h=154&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9nm5764dbppg_v9_main&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=opn.pe_5693e5c6-19d1-4c8a-84cb-85248d6405f9&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=opn.pe_d9408c8e-5724-46a9-b7f1-4bf910a26067&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=osk.d9d02de7c418534587e5be687df727a5&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9plgt00f15xs_abtesting_835b67e1-8ab1-490d-a6ab-e8840fad9bde&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9pltx207s22g_v6_main&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=opn.pe_1e13b6cc-0ab3-4dd6-acf7-218c8c2be53c&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=osk.f5873d89f968cc2d480b0f930e95ae4f&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9p3610rr8qt5_v3_main&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9p9rpk71ggql_v3_main&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9njb654d39wx_v12_main&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=opn.pe_489223ad-97fa-4373-ad93-7f8a6f97c634&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=odswg.d59d4f41-177b-4727-bfd9-f4f300aa3662&w=124&h=154&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9nbckjw55fsv_v6_main&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=opn.pe_73774666-380a-41c6-9f06-23e82f450df0&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=osk.3ba19440475e4b7cfe01e20a1b08771e&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=odswg.bc00fe98-00b2-46fc-96fe-f385f609e12f&w=124&h=154&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9n7hl5s06zk0_abtesting_d91bec27-6f2b-4b8c-b317-00677b8039c6&w=86&h=86&c=1&rs=1&p=0
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2800
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7890
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10855
comments 0

What is Latrodectus malware?

Latrodectus is a type of malware known as a "loader," which is designed to download and install additional malicious software onto a compromised computer. It is believed to have been developed by the same individuals or group behind the IcedID trojan, a sophisticated and widespread banking malware.

Since 2023, Latrodectus has been extensively used by a variety of threat actors, including advanced persistent threat (APT) groups such as TA578 and TA577, which was previously observed delivering the Qbot malware, a banking trojan family.

Latrodectus is typically delivered as part of multi-stage attacks, which often begin with a phishing email containing a malicious JavaScript file attachment. However, it has also been known to be dropped by other malware, including the DanaBot trojan.

One of the key features that has allowed security researchers to link Latrodectus to the IcedID authors is the use of a similar command and control (C2) infrastructure. C2 servers are used by malware to communicate with their operators, receive instructions, and exfiltrate data.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Latrodectus malware technical details

The primary functionality of Latrodectus is to receive commands from the attackers and perform them.

Some of the key capabilities of Latrodectus include:

  • Getting a list of filenames of files located on the desktop of the infected machine.
  • Listing all the processes currently running on the device.
  • Gathering and transmitting additional system information about the endpoint, such as the OS version and hardware specs.
  • Launching of executable files to install malware or to perform other malicious actions.
  • Detonating dynamic link library (DLL) files.
  • Using Windows command prompt to execute commands.

A typical Latrodectus infection chain begins with a JavaScript file that is responsible for downloading a malicious .msi file, which then leads to the deployment of the final payload on the system.

The malware implements obfuscation techniques, such as encrypting strings, to make it more difficult for researchers to analyze. It communicates with its command and control (C2) server via HTTPS, with both requests and responses encrypted using RC4 and base64 encoding.

Furthermore, Latrodectus has a built-in sandbox detection mechanism that works by enumerating the number of active processes on the device and checking for the presence of a MAC address.

The malware can establish a scheduled task for persistence, ensuring that it remains active on the infected machine even after a reboot. It also verifies if the computer is already infected with Latrodectus and exits execution if the result is positive.

Latrodectus execution process

Let’s detonate a sample of the Latrodectus malware in the ANY.RUN sandbox to observe its execution chain.

The infiltration process of the Latrodectus malware involves a sequence of steps that ultimately lead to its successful operation on a target system.

Upon launching a JavaScript file, it automatically retrieves an installer MSI. This MSI file implants a Latrodectus Dynamic Link Library (DLL) onto the system, allowing the malware to maintain persistence even after the system is rebooted.

Latrodectus process graph in ANY.RUN Latrodectus process graph in ANY.RUN

Once implanted, the Latrodectus malware establishes communication with its command-and-control (C2) server, providing remote access to the infected device for malicious actors.

Gathering threat intelligence on Latrodectus malware

To collect up-to-date intelligence on Latrodectus, use Threat Intelligence Lookup.

This service gives you access to a vast database filled with insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox.

With over 40 customizable search parameters, including IPs, domains, file names, and process artifacts, you can efficiently gather relevant data on threats like Latrodectus.

Latrodectus ANY.RUN Search results for Latrodectus in Threat Intelligence Lookup

For example, you can search directly for the threat name or use related indicators like hash values or network connections. Submitting a query such as threatName:"latrodectus" AND domainName:"" will generate a list of other data extracted from Lumma samples along with sandbox sessions that you can explore in detail to gain comprehensive insights into this malware’s behavior.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Latrodectus malware distribution methods

Phishing emails are the most common attack vector by threat actors for distributing Latrodectus malware. These emails are typically designed to appear as if they have been sent from a legitimate organization or individual, to trick the recipient into opening an attached file or clicking on a malicious link.

In one particular campaign, the threat actor group TA578 was observed to be spreading Latrodectus as part of a scheme that involved accusing target companies of copyright infringement. The phishing emails in this campaign were designed to look like they were sent from a legitimate organization.

In another instance, a fake Azure page was used to initiate the infection chain.

Conclusion

Latrodectus is a noteworthy loader that presents a challenge due to its widespread use by professional cyber criminal groups. Its capacity to deploy payloads, along with its advanced obfuscation and evasion methods, as well as continuous development contribute to its potential to become an even more serious threat.

ANY.RUN is a cloud-based service that can be used to safely analyze suspicious files and URLs, including Latrodectus malware. It allows you to observe malware behavior and collect indicators of compromise in a secure environment. Using ANY.RUN can help you understand Latrodectus's tactics and improve your defenses against it.

Create your ANY.RUN account – it’s free!

HAVE A LOOK AT

Wshrat screenshot
Wshrat
wshrat rat trojan
WSHRAT is a Remote Access Trojan — a malware that allows the attackers to take over the infected machines. The RAT has been in circulation since 2013 and it is arguably most notable for the numerous versions released into the wild.
Read More
Remcos screenshot
Remcos is a commercially distributed remote administration and surveillance tool that has been widely observed in unauthorized deployments, where threat actors use it to perform remote actions on compromised machines. It is actively maintained by its vendor, with new versions and feature updates released on a frequent, near-monthly basis.
Read More
Akira Ransomware screenshot
Akira Ransomware emerged in March 2023 and compromised over 250 organizations by January 2024 with approximately $42 million in ransom payments. It employs double extortion tactics exfiltrating data before encryption and threatening to publish it on a dedicated website.
Read More
PXA Stealer screenshot
PXA Stealer
pxastealer
PXA Stealer is an information-stealing malware that targets individuals and organizations in 60+ countries. It spreads via phishing, archives, and fake software updates. DLL sideloading, decoy documents, and obfuscation help it evade security tools. Exfiltrated data is exfiltrated and monetized through underground marketplaces.
Read More
Razr screenshot
Razr
razr
Razr is a destructive ransomware that infiltrates systems to encrypt files, rendering them inaccessible to users. It appends the ".razr" extension to the encrypted files and drops a ransom note, typically named "README.txt," instructing victims on how to pay the ransom to obtain the decryption key. The malware often spreads through phishing emails with malicious attachments or by exploiting vulnerabilities in software and operating systems. Razr employs strong encryption algorithms, making it challenging to decrypt files without the attackers' key.
Read More
Kamasers screenshot
Kamasers
kamasers
Kamasers is a multi-functional DDoS botnet malware that transforms infected machines into remotely controlled attack nodes. It combines network-layer flooding capabilities, resilient command-and-control (C2), and payload delivery, making it not just a disruption tool but a gateway to broader compromise.
Read More