Latrodectus, also known as IceNova and BLACKWIDOW, is a Windows malware loader first discovered in October 2023. It is used in financially motivated campaigns to establish initial access and deliver additional payloads, including IcedID and Lumma Stealer, and is associated with ransomware-enabling activity. Threat actors distributing it include TA577, TA578, and Storm-0249. Observed campaigns have targeted financial, automotive, and business sectors, as well as U.S. users through tax-themed phishing.
Delivery commonly involves phishing emails with malicious attachments or links, followed by obfuscated JavaScript and MSI installation stages. Other campaigns use counterfeit software installers or compromised websites displaying fake CAPTCHA prompts that induce users to execute malicious commands through ClickFix-style social engineering. Execution chains abuse legitimate Windows utilities, and some use DLL sideloading.
Latrodectus supports downloading and executing executables, DLLs, and shellcode; command execution; process termination; self-updates; and extensive host and domain reconnaissance. It enumerates processes, files, users, network configuration, domain relationships, and installed security products, and transmits collected information through encrypted command-and-control communications. Persistence includes scheduled tasks and startup mechanisms, with implementation varying by version.
Defense-evasion features include dynamic API resolution, encrypted strings, packing, misleading component metadata, debugger detection, and sandbox checks based on process counts and network-adapter information. It can delete its own executable while running by abusing NTFS alternate data streams. Latrodectus shares technical characteristics and infrastructure with IcedID and includes functionality specifically for deploying IcedID payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Threat Details and IOCs Malware: ... Latrodectus ...
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.
Latrodectus is a downloader first discovered by Walmart back in October of 2023... During the Threat Labs hunting activities we discovered a new version of the Latrodectus payload, version 1.4.
Latrodectus is a loader primarily used for initial access and payload delivery. It features dynamic command-and-control (C2) configurations, anti-analysis features such as minimum process count and network adapter check, C2 check-in behavior that splits POST data between the Cookie header and POST data.
2024-03-07 (THURSDAY): LATRODECTUS INFECTION LEADS TO LUMMA STEALER
On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.
Latrodectus, also known as IceNova Backdoor ... is a family of malware that has been observed lately in campaigns linked to groups such as Trickbot ( WIZARD SPIDER ) and Conti (and potentially, in Ransomware deliveries), in addition to being attributed to developers from IcedID . Therefore, Latrodectus has been highlighted as a potential threat and is used as a Loader for other malware.
43 distinct techniques documented for this family, organized by ATT&CK tactic.
278 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
108 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader mentionné indirectement dans l’évaluation de liens potentiels entre C2Looper, Oyster et un acteur commun.
A lightweight loader/downloader assessed to be built by the operators behind IcedID. It is delivered via phishing and malicious ads, often masquerades as trusted software, executes as a DLL via rundll32, persists via a COM-created scheduled task, evades sandboxes, and communicates over HTTPS to C2 infrastructure using a distinctive self-signed certificate and /live/ POST path. It serves as an initial-stage intrusion tool and has delivered follow-on payloads including IcedID and Brute Ratel C4; newer builds add a BackConnect (VNC) module.
Double Trouble: Latrodectus and ACR Stealer observed spreading via Google Authenticator Phishing Site
Latrodectus2
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.