LATENTBOT
LatentBot is a modular Windows backdoor that has been active since at least 2013 and is commonly described as highly obfuscated.
Profile source: Mallory opens in a new tabLATENTBOT
Family profile
LatentBot is a modular Windows backdoor that has been active since at least 2013 and is commonly described as highly obfuscated. It has been observed in exploit-driven and document-based intrusion chains, including campaigns exploiting CVE-2017-0199 in Microsoft Office and infections delivered through the RIG exploit kit. In those operations, victims were lured into opening crafted Office documents or redirected through exploit-kit infrastructure, after which LatentBot was downloaded and executed on the compromised host.
LatentBot is associated with multi-stage delivery chains that use decoy documents and process termination to reduce user suspicion during exploitation. Reported variants employ multiple code-injection and execution-transfer techniques, including injection into legitimate Windows processes and browser-related injection methods. The malware has also been observed establishing persistence on infected Windows systems.
The family is characterized as an all-purpose modular backdoor and has been linked to plugin-based functionality. High-confidence reporting ties it to post-compromise command-and-control activity and long-running criminal malware operations, including historical association with Pony infostealer campaigns. Its command-and-control design has been notable enough that later malware, including newer Grandoreiro variants, adopted a closely matching beaconing pattern based on an ACTION=HELLO style check-in and identifier-based communications.
LatentBot targets Windows environments and is primarily relevant to financially motivated and exploit-kit-enabled intrusion activity. Confirmed delivery vectors include malicious Office documents exploiting CVE-2017-0199 and exploit-kit traffic associated with RIG.
Capabilities
- Defense Evasion
- Persistence
- Post Exploitation
- Process Injection
Exploited software
Vulnerabilities linked to LATENTBOT
1 CVEsMITRE ATT&CK
LATENTBOT in ATT&CK
9 distinct techniquesReporting
Research mentioning LATENTBOT
Grandoreiro Banking Trojan with New TTPs | Zscaler Blog
The Grandoreiro banking trojan has re-emerged as a large-scale global threat, with researchers reporting phishing-driven campaigns that now target more than 1,500 banking applications and websites across 60+ countries. IBM X-Force said recent activity has used emails impersonating government entities in Mexico, Argentina, and South Africa, while other reporting tied the lures to organizations such as Mexico’s SAT and CFE and South Africa’s SARS. The malware, long associated with Latin America, has expanded into Europe, Africa, and the Indonesia-Pacific region and has been linked to financial fraud affecting multiple sectors.