Skip to content

LATENTBOT

LatentBot is a modular Windows backdoor that has been active since at least 2013 and is commonly described as highly obfuscated.

Profile source: Mallory opens in a new tab

LATENTBOT

Family profile

LatentBot is a modular Windows backdoor that has been active since at least 2013 and is commonly described as highly obfuscated. It has been observed in exploit-driven and document-based intrusion chains, including campaigns exploiting CVE-2017-0199 in Microsoft Office and infections delivered through the RIG exploit kit. In those operations, victims were lured into opening crafted Office documents or redirected through exploit-kit infrastructure, after which LatentBot was downloaded and executed on the compromised host.

LatentBot is associated with multi-stage delivery chains that use decoy documents and process termination to reduce user suspicion during exploitation. Reported variants employ multiple code-injection and execution-transfer techniques, including injection into legitimate Windows processes and browser-related injection methods. The malware has also been observed establishing persistence on infected Windows systems.

The family is characterized as an all-purpose modular backdoor and has been linked to plugin-based functionality. High-confidence reporting ties it to post-compromise command-and-control activity and long-running criminal malware operations, including historical association with Pony infostealer campaigns. Its command-and-control design has been notable enough that later malware, including newer Grandoreiro variants, adopted a closely matching beaconing pattern based on an ACTION=HELLO style check-in and identifier-based communications.

LatentBot targets Windows environments and is primarily relevant to financially motivated and exploit-kit-enabled intrusion activity. Confirmed delivery vectors include malicious Office documents exploiting CVE-2017-0199 and exploit-kit traffic associated with RIG.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation
  • Process Injection

Exploited software

Vulnerabilities linked to LATENTBOT

1 CVEs

MITRE ATT&CK

LATENTBOT in ATT&CK

9 distinct techniques

Reporting

Research mentioning LATENTBOT

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.