Description
Latrodectus is a malware loader that emerged in late 2023 with rapid evolution and new payload features that caught researchers' attention in 2024. Distributed through phishing campaigns and search engine poisoning, it establishes persistence and downloads payloads such as remote access trojans and command and control frameworks. Researchers view it as the successor to IcedID's loader role, and its developers iterate quickly to defeat detection and analysis.
Stats
- First seen
- March 2024
- Last seen
- September 2026
MITRE ATT&CK techniques
43 techniques across 10 tactics.
TA0002 Execution
TA0005 Stealth
- T1027Obfuscated Files or Information
- T1036Masquerading
- T1036.005Match Legitimate Resource Name or Location
- T1070Indicator Removal
- T1070.004File Deletion
- T1140Deobfuscate/Decode Files or Information
- T1218System Binary Proxy Execution
- T1497Virtualization/Sandbox Evasion
- T1497.001System Checks
- T1564Hide Artifacts
- T1564.004NTFS File Attributes
- T1622Debugger Evasion
TA0007 Discovery
- T1016System Network Configuration Discovery
- T1033System Owner/User Discovery
- T1057Process Discovery
- T1069Permission Groups Discovery
- T1069.002Domain Groups
- T1082System Information Discovery
- T1083File and Directory Discovery
- T1087Account Discovery
- T1087.002Domain Account
- T1135Network Share Discovery
- T1482Domain Trust Discovery
- T1518Software Discovery
- T1518.001Security Software Discovery
TA0009 Collection
- T1005Data from Local System
TA0011 Command and Control
TA0010 Exfiltration
- T1041Exfiltration Over C2 Channel
TA0040 Impact
- T1529System Shutdown/Reboot
Associated groups
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.Latrodectus |
| Script-JS.Downloader.Latrodectus |
| Script-JS.Trojan.Latrodectus |
| Win32.Ransomware.Latrodectus |
| Win32.Trojan.Latrodectus |
| Win64.Spyware.Latrodectus |
| Win64.Trojan.Latrodectus |

