Threat Advisory

Latrodectus Malware Loader Emerges as IcedID's Successor in Phishing Campaigns

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

LATRODECTUS is a new malware loader gaining popularity among cybercriminals. It shares similarities with ICEDID, particularly in its command handler for downloading and executing encrypted payloads. Proofpoint and Team Cymru identified a strong connection between the network infrastructure of both LATRODECTUS and ICEDID. Researchers reported a rise in email campaigns delivering LATRODECTUS since March 2024, typically involving oversized JavaScript files that install a remotely hosted MSI file.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

LATRODECTUS is a new malware loader gaining popularity among cybercriminals. It shares similarities with ICEDID, particularly in its command handler for downloading and executing encrypted payloads. Proofpoint and Team Cymru identified a strong connection between the network infrastructure of both LATRODECTUS and ICEDID. Researchers reported a rise in email campaigns delivering LATRODECTUS since March 2024, typically involving oversized JavaScript files that install a remotely hosted MSI file.[emaillocker id="1283"]

LATRODECTUS is a lightweight malware loader with 11 command handlers for enumeration and execution. It is a DLL with four exports and uses straightforward encryption and anti-analysis techniques, including debugger detection, sandbox evasion, and WOW64 checks. It masquerades as a Bitdefender kernel-mode driver and uses a variety of methods to obscure its imports until runtime. After unpacking, it sets up a scheduled task for persistence and uses self-deletion techniques to hinder incident response.

The malware encrypts its requests with base64 and RC4, using a hardcoded password. It communicates with command-and-control (C2) servers to execute various commands, including downloading and executing files, collecting system information, and performing system discovery. LATRODECTUS also integrates techniques to avoid detection, such as using jitter for beaconing intervals and resetting request counters. It supports various payloads, including ICEDID components, shellcode, and DLLs.

LATRODECTUS represents a significant threat due to its sophisticated techniques and capabilities. With the decline of other loaders like QBOT and ICEDID, new threats like LATRODECTUS and PIKABOT are emerging. Security teams must remain vigilant and update their defenses to detect and mitigate these evolving malware threats.

THREAT PROFILE:

Tactic Technique Id Technique
Execution T1059 Command and Scripting Interpreter
T1047 Windows Management Instrumentation
T1053 Scheduled Task/Job
Defense Evasion T1027 Obfuscated Files or Information
T1218 System Binary Proxy Execution
T1055 Process Injection
T1070 Indicator Removal

REFERENCES:

The following reports contain further technical details:

https://thehackernews.com/2024/05/latrodectus-malware-loader-emerges-as.html

[/emaillocker]
crossmenu