Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Latrodectus

168
Global rank
175 infographic chevron month
Month rank
156 infographic chevron week
Week rank

Latrodectus is a malicious loader that is used by threat actors to gain a foothold on compromised devices and deploy additional malware. It has been associated with the IcedID trojan and has been used by APT groups in targeted attacks. The malware can gather system information, launch executables, and detect sandbox environments. It uses encryption and obfuscation to evade detection and can establish persistence on the infected device.

Loader
Type
Unknown
Origin
1 August, 2023
First seen
11 August, 2026
Last seen
Also known as
Unidentified 111
BLACKWIDOW
IceNova

How to analyze Latrodectus with ANY.RUN

Type
Unknown
Origin
1 August, 2023
First seen
11 August, 2026
Last seen

IOCs

IP addresses
2.16.204.145
48.209.138.189
48.209.138.168
172.64.154.167
48.192.1.64
2.16.204.135
40.126.32.133
23.52.181.141
172.211.123.250
162.159.36.2
74.178.240.51
74.178.76.128
88.221.92.192
48.192.1.65
88.221.169.205
48.209.6.48
40.126.32.68
2.16.241.218
2.16.241.201
172.211.123.248
Hashes
ec29ce8537e112869dfccb8a57574ebd01eecd7ff5c9fff54fdc1b05ea8941b3
62a2cb5aa12f592f3994d8e7a6483ae549b10df8f7c8064a91e9ccb7a2d53bdb
77bf693b39878fdfe8dae97ae541b54ebe3179ea4a98225713908eb1f49a4158
6f4ece9eef5c4e518ad56a6f82d14e95f93e4e5d07b1cb8d22de8666d7ac3d7f
4256488766553496d02c7dc5868938e34f24028f9841a5021560781e6f5b8d6e
298999caaa697082b5fd80903b1966482f211c921ab1ff74bb239c0db3337022
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
a8d081072ddd97380e854b9b664eaddcfafe6c28ee51c435f6d6b99919f1a105
8b4e15762e934422367a0fe0085258f7e73a294546680e3801e335a64fbdddd5
75da533888189d13fc340d40637b9fc07a3f732e3fcf33ec300f4c7268790a62
907f2709d1d3c8fa26294938f4080bc477e62281c4c50a082c22db0195cda663
22ca9415e294d9c3ec3384b9d08cdaf5164af73b4e4c251559e09e529c843ea6
474d668707f1cb929fef1e3798b71b632e50675bd1a9dceaab90c9587f72f680
3d0361a85adfcd35d0de74135723a75b646965e775188f7dcdd35e3e42db788e
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
9c70f766d3b84fc2bb298efa37cc9191f28bec336329cc11468cfadbc3b137f4
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
b3ece279943b28c8d855ec86ac1ce53bdfb6a709240d653508764493a75f7518
4ecedb9c1f3dd0d0e3aeb86146561b3d7e58656cbdbed1a39b91737b52ec7f2c
e758273c25fbad804fe884584e2797caefbbd1c2877dfd6f87ab1340cd25252e
Domains
google.com
th.bing.com
www.bing.com
settings-win.data.microsoft.com
activation-v2.sls.microsoft.com
fe3cr.delivery.mp.microsoft.com
slscr.update.microsoft.com
client.wns.windows.com
login.live.com
go.microsoft.com
clients2.googleusercontent.com
assets.constantcontact.com
edge.microsoft.com
copilot.microsoft.com
acroipm2.adobe.com
api.edgeoffer.microsoft.com
9868svhbb.cc.rs6.net
ocsp.digicert.com
www.microsoft.com
oneocsp.microsoft.com
URLs
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
https://th.bing.com/th?id=odswg.1e1da29b-91ea-4d2e-ac12-df81dfa2c53d&w=124&h=154&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9nm5764dbppg_v9_main&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=opn.pe_5693e5c6-19d1-4c8a-84cb-85248d6405f9&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=opn.pe_d9408c8e-5724-46a9-b7f1-4bf910a26067&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=osk.d9d02de7c418534587e5be687df727a5&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9plgt00f15xs_abtesting_835b67e1-8ab1-490d-a6ab-e8840fad9bde&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9pltx207s22g_v6_main&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=opn.pe_1e13b6cc-0ab3-4dd6-acf7-218c8c2be53c&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=osk.f5873d89f968cc2d480b0f930e95ae4f&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9p3610rr8qt5_v3_main&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9p9rpk71ggql_v3_main&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9njb654d39wx_v12_main&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=opn.pe_489223ad-97fa-4373-ad93-7f8a6f97c634&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=odswg.d59d4f41-177b-4727-bfd9-f4f300aa3662&w=124&h=154&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9nbckjw55fsv_v6_main&w=86&h=86&c=1&rs=1&p=0
https://th.bing.com/th?id=opn.pe_73774666-380a-41c6-9f06-23e82f450df0&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=osk.3ba19440475e4b7cfe01e20a1b08771e&w=140&h=96&c=1&rs=1&p=0
https://th.bing.com/th?id=odswg.bc00fe98-00b2-46fc-96fe-f385f609e12f&w=124&h=154&c=1&rs=1&p=0
https://th.bing.com/th?id=ocge.9n7hl5s06zk0_abtesting_d91bec27-6f2b-4b8c-b317-00677b8039c6&w=86&h=86&c=1&rs=1&p=0
Last Seen at

Recent blog posts

post image
How MSSPs Can Prove Their Value When “Nothing...
watchers 1129
comments 0
post image
Enterprise Threat Intelligence Buying Guide:...
watchers 1423
comments 0
post image
ANY.RUN & SentinelOne: One Workspace, Ins...
watchers 3017
comments 0

What is Latrodectus malware?

Latrodectus is a type of malware known as a "loader," which is designed to download and install additional malicious software onto a compromised computer. It is believed to have been developed by the same individuals or group behind the IcedID trojan, a sophisticated and widespread banking malware.

Since 2023, Latrodectus has been extensively used by a variety of threat actors, including advanced persistent threat (APT) groups such as TA578 and TA577, which was previously observed delivering the Qbot malware, a banking trojan family.

Latrodectus is typically delivered as part of multi-stage attacks, which often begin with a phishing email containing a malicious JavaScript file attachment. However, it has also been known to be dropped by other malware, including the DanaBot trojan.

One of the key features that has allowed security researchers to link Latrodectus to the IcedID authors is the use of a similar command and control (C2) infrastructure. C2 servers are used by malware to communicate with their operators, receive instructions, and exfiltrate data.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Latrodectus malware technical details

The primary functionality of Latrodectus is to receive commands from the attackers and perform them.

Some of the key capabilities of Latrodectus include:

  • Getting a list of filenames of files located on the desktop of the infected machine.
  • Listing all the processes currently running on the device.
  • Gathering and transmitting additional system information about the endpoint, such as the OS version and hardware specs.
  • Launching of executable files to install malware or to perform other malicious actions.
  • Detonating dynamic link library (DLL) files.
  • Using Windows command prompt to execute commands.

A typical Latrodectus infection chain begins with a JavaScript file that is responsible for downloading a malicious .msi file, which then leads to the deployment of the final payload on the system.

The malware implements obfuscation techniques, such as encrypting strings, to make it more difficult for researchers to analyze. It communicates with its command and control (C2) server via HTTPS, with both requests and responses encrypted using RC4 and base64 encoding.

Furthermore, Latrodectus has a built-in sandbox detection mechanism that works by enumerating the number of active processes on the device and checking for the presence of a MAC address.

The malware can establish a scheduled task for persistence, ensuring that it remains active on the infected machine even after a reboot. It also verifies if the computer is already infected with Latrodectus and exits execution if the result is positive.

Latrodectus execution process

Let’s detonate a sample of the Latrodectus malware in the ANY.RUN sandbox to observe its execution chain.

The infiltration process of the Latrodectus malware involves a sequence of steps that ultimately lead to its successful operation on a target system.

Upon launching a JavaScript file, it automatically retrieves an installer MSI. This MSI file implants a Latrodectus Dynamic Link Library (DLL) onto the system, allowing the malware to maintain persistence even after the system is rebooted.

Latrodectus process graph in ANY.RUN Latrodectus process graph in ANY.RUN

Once implanted, the Latrodectus malware establishes communication with its command-and-control (C2) server, providing remote access to the infected device for malicious actors.

Gathering threat intelligence on Latrodectus malware

To collect up-to-date intelligence on Latrodectus, use Threat Intelligence Lookup.

This service gives you access to a vast database filled with insights from millions of malware analysis sessions conducted in the ANY.RUN sandbox.

With over 40 customizable search parameters, including IPs, domains, file names, and process artifacts, you can efficiently gather relevant data on threats like Latrodectus.

Latrodectus ANY.RUN Search results for Latrodectus in Threat Intelligence Lookup

For example, you can search directly for the threat name or use related indicators like hash values or network connections. Submitting a query such as threatName:"latrodectus" AND domainName:"" will generate a list of other data extracted from Lumma samples along with sandbox sessions that you can explore in detail to gain comprehensive insights into this malware’s behavior.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Latrodectus malware distribution methods

Phishing emails are the most common attack vector by threat actors for distributing Latrodectus malware. These emails are typically designed to appear as if they have been sent from a legitimate organization or individual, to trick the recipient into opening an attached file or clicking on a malicious link.

In one particular campaign, the threat actor group TA578 was observed to be spreading Latrodectus as part of a scheme that involved accusing target companies of copyright infringement. The phishing emails in this campaign were designed to look like they were sent from a legitimate organization.

In another instance, a fake Azure page was used to initiate the infection chain.

Conclusion

Latrodectus is a noteworthy loader that presents a challenge due to its widespread use by professional cyber criminal groups. Its capacity to deploy payloads, along with its advanced obfuscation and evasion methods, as well as continuous development contribute to its potential to become an even more serious threat.

ANY.RUN is a cloud-based service that can be used to safely analyze suspicious files and URLs, including Latrodectus malware. It allows you to observe malware behavior and collect indicators of compromise in a secure environment. Using ANY.RUN can help you understand Latrodectus's tactics and improve your defenses against it.

Create your ANY.RUN account – it’s free!

HAVE A LOOK AT

INC Ransomware screenshot
INC Ransomware is a ransomware-as-a-service (RaaS) spotted in mid-2023. It targets industries like retail, real estate, finance, healthcare, and education, primarily in the U.S. and UK. It encrypts and exfiltrates data demanding a ransom. It employs advanced evasion techniques, destroys backup, and abuses legitimate system tools at all the stages of the kill chain.
Read More
Oyster screenshot
Oyster
oyster
Oyster (also seen in reporting as Broomstick or CleanUpLoader) is a Windows backdoor/loader actively used in multi-stage intrusion campaigns. Recent campaigns weaponize SEO-poisoning and malvertising to trick IT and dev users into downloading trojanized installers (PuTTY, WinSCP, Microsoft Teams, etc.), which then drop Oyster to establish a persistent foothold and load additional payloads (often leading to data theft or ransomware).
Read More
Wshrat screenshot
Wshrat
wshrat rat trojan
WSHRAT is a Remote Access Trojan — a malware that allows the attackers to take over the infected machines. The RAT has been in circulation since 2013 and it is arguably most notable for the numerous versions released into the wild.
Read More
Quasar RAT screenshot
Quasar RAT
quasar trojan rat
Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.
Read More
LockBit screenshot
LockBit
lockbit
LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.
Read More
Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More