EXECUTIVE SUMMARY
LATRODECTUS is a new malware loader gaining popularity among cybercriminals. It shares similarities with ICEDID, particularly in its command handler for downloading and executing encrypted payloads. Proofpoint and Team Cymru identified a strong connection between the network infrastructure of both LATRODECTUS and ICEDID. Researchers reported a rise in email campaigns delivering LATRODECTUS since March 2024, typically involving oversized JavaScript files that install a remotely hosted MSI file.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
LATRODECTUS is a new malware loader gaining popularity among cybercriminals. It shares similarities with ICEDID, particularly in its command handler for downloading and executing encrypted payloads. Proofpoint and Team Cymru identified a strong connection between the network infrastructure of both LATRODECTUS and ICEDID. Researchers reported a rise in email campaigns delivering LATRODECTUS since March 2024, typically involving oversized JavaScript files that install a remotely hosted MSI file.[emaillocker id="1283"]
LATRODECTUS is a lightweight malware loader with 11 command handlers for enumeration and execution. It is a DLL with four exports and uses straightforward encryption and anti-analysis techniques, including debugger detection, sandbox evasion, and WOW64 checks. It masquerades as a Bitdefender kernel-mode driver and uses a variety of methods to obscure its imports until runtime. After unpacking, it sets up a scheduled task for persistence and uses self-deletion techniques to hinder incident response.
The malware encrypts its requests with base64 and RC4, using a hardcoded password. It communicates with command-and-control (C2) servers to execute various commands, including downloading and executing files, collecting system information, and performing system discovery. LATRODECTUS also integrates techniques to avoid detection, such as using jitter for beaconing intervals and resetting request counters. It supports various payloads, including ICEDID components, shellcode, and DLLs.
LATRODECTUS represents a significant threat due to its sophisticated techniques and capabilities. With the decline of other loaders like QBOT and ICEDID, new threats like LATRODECTUS and PIKABOT are emerging. Security teams must remain vigilant and update their defenses to detect and mitigate these evolving malware threats.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Execution | T1059 | Command and Scripting Interpreter |
| T1047 | Windows Management Instrumentation | |
| T1053 | Scheduled Task/Job | |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1218 | System Binary Proxy Execution | |
| T1055 | Process Injection | |
| T1070 | Indicator Removal |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/05/latrodectus-malware-loader-emerges-as.html
[/emaillocker]