Netskope Threat Labs

Latrodectus

ATP Sandbox Adv. HeuristicsNetskope IPS

Latrodectus is a malware loader that emerged in late 2023 with rapid evolution and new payload features that caught researchers' attention in 2024. Distributed through phishing campaigns and search engine poisoning, it establishes persistence and downloads payloads such as remote access trojans and command and control frameworks. Researchers view it as the successor to IcedID's loader role, and its developers iterate quickly to defeat detection and analysis.

First seen
March 2024
Last seen
September 2026

43 techniques across 10 tactics.

TA0001 Initial Access

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

TA0008 Lateral Movement

TA0009 Collection

  • T1005Data from Local System

TA0011 Command and Control

TA0010 Exfiltration

  • T1041Exfiltration Over C2 Channel

TA0040 Impact

  • T1529System Shutdown/Reboot
Alert Name
ByteCode-MSIL.Trojan.Latrodectus
Script-JS.Downloader.Latrodectus
Script-JS.Trojan.Latrodectus
Win32.Ransomware.Latrodectus
Win32.Trojan.Latrodectus
Win64.Spyware.Latrodectus
Win64.Trojan.Latrodectus