LatentBot is a modular Windows backdoor that has been active since at least 2013 and is commonly described as highly obfuscated. It has been observed in exploit-driven and document-based intrusion chains, including campaigns exploiting CVE-2017-0199 in Microsoft Office and infections delivered through the RIG exploit kit. In those operations, victims were lured into opening crafted Office documents or redirected through exploit-kit infrastructure, after which LatentBot was downloaded and executed on the compromised host.
LatentBot is associated with multi-stage delivery chains that use decoy documents and process termination to reduce user suspicion during exploitation. Reported variants employ multiple code-injection and execution-transfer techniques, including injection into legitimate Windows processes and browser-related injection methods. The malware has also been observed establishing persistence on infected Windows systems.
The family is characterized as an all-purpose modular backdoor and has been linked to plugin-based functionality. High-confidence reporting ties it to post-compromise command-and-control activity and long-running criminal malware operations, including historical association with Pony infostealer campaigns. Its command-and-control design has been notable enough that later malware, including newer Grandoreiro variants, adopted a closely matching beaconing pattern based on an ACTION=HELLO style check-in and identifier-based communications.
LatentBot targets Windows environments and is primarily relevant to financially motivated and exploit-kit-enabled intrusion activity. Confirmed delivery vectors include malicious Office documents exploiting CVE-2017-0199 and exploit-kit traffic associated with RIG.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2017-0199 Vulnerable Products: Microsoft Office 2007 SP3/2010 SP2/2013 SP1/2016, Vista SP2, Server 2008 SP2, Windows 7 SP1, Windows 8.1 Associated Malware: FINSPY, LATENTBOT, Dridex Mitigation: Update affected Microsoft products with the latest security patches | CVE-2017-0199 ... Associated Malware: FINSPY, LATENTBOT, Dridex
9 distinct techniques documented for this family, organized by ATT&CK tactic.
2017-04-25 - "GOOD MAN" CAMPAIGN RIG EK SENDS LATENTBOT ... hurtmehard[.]net - "Good Man" gate ... end.chaggama[.]com - Rig EK
2017-04-25-Rig-EK-flash-exploit.swf ... File description: Rig EK flash exploit seen on 2017-04-25
According to U.S. Government technical analysis, malicious cyber actors most often exploited vulnerabilities in Microsoft’s Object Linking and Embedding (OLE) technology. OLE allows documents to contain embedded content from other applications such as spreadsheets.
U.S. Government reporting has identified the top 10 most exploited vulnerabilities by state, nonstate, and unattributed cyber actors from 2016 to 2019 as follows: CVE-2017-11882, CVE-2017-0199, CVE-2017-5638, CVE-2012-0158, CVE-2019-0604, CVE-2017-0143, CVE-2018-4878, CVE-2017-8759, CVE-2015-1641, and CVE-2018-7600.
37.72.175[.]221 port 80 - 37.72.175[.]221 - Latentbot post-infection traffic
PAYLOAD (LATENTBOT): SHA256 hash: 092fd4caf46ec36e07fdc9c8b156ce05cda0fb2abd7c49ba8dddfe8ac6cdbb67 ... File location: C:\Users\[username]\AppData\Local\Temp\ [various alphanumeric characters] .exe
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family referenced because Grandoreiro’s 2022 command-and-control traffic and beaconing pattern are described as identical to it, including ACTION=HELLO and ID-based communication.
Latentbot is the payload delivered in the described Rig EK infection chain and establishes persistence on the infected Windows host, generating post-infection traffic associated with the GrayBird/Latentbot family.
LatentBot is referenced as a malware strain whose C2 communication pattern and techniques were adopted by Grandoreiro.
Mentioned as an honorable mention for being written in Delphi.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.