On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.
Latrodectus
Latrodectus, also known as IceNova and BlackWidow, is a Windows malware family primarily used as a downloader with backdoor functionality.
Profile source: Mallory opens in a new tabLatrodectus
Family profile
Latrodectus, also known as IceNova and BlackWidow, is a Windows malware family primarily used as a downloader with backdoor functionality. It emerged in late 2023 and is widely assessed to be associated with the same cybercrime ecosystem behind IcedID, with multiple vendors describing it as a likely successor or replacement within that tooling lineage. The malware is used by financially motivated threat actors and initial-access brokers to establish a foothold, profile infected systems, execute attacker-supplied commands, and retrieve additional payloads for follow-on intrusion activity.
Latrodectus commonly executes as a DLL launched through rundll32 and has been observed in infection chains involving scripts, MSI installers, JavaScript, malicious spam, phishing pages, fake software or security updates, and ClickFix-style social engineering. Campaigns have used financially themed lures, tax-related themes, cloned brand pages, and impersonation of trusted software and services such as Google Authenticator, Google Safety Centre, and security products. It has also been delivered by other malware, including DanaBot, and has appeared alongside Brute Ratel C4 in multi-stage campaigns.
Once active, Latrodectus performs host profiling and reconnaissance, including collection of the current username and broader system metadata such as operating system, architecture, computer name, domain context, uptime, and network configuration. Observed command templates and decrypted strings show support for discovery of domain trusts, network views, workstation configuration, group membership, and antivirus products, including enumeration of privileged domain groups. The malware communicates with command-and-control infrastructure over HTTP or HTTPS, including encoded POST-based exchanges, and exfiltrates encrypted system information to register and manage infected hosts.
Latrodectus includes anti-analysis and defense-evasion features such as custom string obfuscation and environment checks intended to identify sandboxed systems. It has also been observed establishing persistence through Windows scheduled tasks created via COM. The malware supports arbitrary command execution and staged delivery of additional DLL or EXE payloads, making it a flexible access platform rather than a single-purpose implant.
Operationally, Latrodectus has been used to deliver or facilitate deployment of additional malware including IcedID, Brute Ratel C4, and BackConnect or VNC-style modules that enable hands-on-keyboard access. Its presence is therefore often a precursor to broader post-compromise activity. Victimology and tradecraft observed to date align most strongly with financially motivated cybercrime operations rather than nation-state activity.
Capabilities
- Defense Evasion
- Exfiltration
- Persistence
- Post Exploitation
- Reconnaissance
Reported operators
Threat actors
11 named in public reportingOn 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.
Latrodectus is a downloader used by adversaries to execute arbitrary commands and deliver additional payloads, frequently leveraging financially-themed lures.
Latrodectus is a downloader used by adversaries to execute arbitrary commands and deliver additional payloads, frequently leveraging financially-themed lures.
Latrodectus, also known as IceNova Backdoor ... is a family of malware that has been observed lately in campaigns linked to groups such as Trickbot ( WIZARD SPIDER ) and Conti (and potentially, in Ransomware deliveries), in addition to being attributed to developers from IcedID . Therefore, Latrodectus has been highlighted as a potential threat and is used as a Loader for other malware.
Latrodectus, also known as IceNova Backdoor ... is a family of malware that has been observed lately in campaigns linked to groups such as Trickbot ( WIZARD SPIDER ) and Conti (and potentially, in Ransomware deliveries), in addition to being attributed to developers from IcedID . Therefore, Latrodectus has been highlighted as a potential threat and is used as a Loader for other malware.
Latrodectus, also known as IceNova Backdoor ... is a family of malware that has been observed lately in campaigns linked to groups such as Trickbot ( WIZARD SPIDER ) and Conti (and potentially, in Ransomware deliveries), in addition to being attributed to developers from IcedID . Therefore, Latrodectus has been highlighted as a potential threat and is used as a Loader for other malware.
The tweet details a Latrodectus infection leveraging phishing links to redirect victims to a javascript file, which ultimately loads LummaStealer Malware.
LUNAR SPIDER’s recent campaign used Latrodectus, a heavily obfuscated JavaScript loader, to deliver Brute Ratel C4 payloads targeting the financial sector.
Bumblebee and Latrodectus, which are both malware loaders, are designed to steal personal data, along with downloading and executing additional payloads onto compromised hosts.
In addition to OysterLoader, Expel discovered the Rhysida threat actors were also using Latrodectus malware in its campaign...
Exploited software
Vulnerabilities linked to Latrodectus
1 CVEsMITRE ATT&CK
Latrodectus in ATT&CK
76 distinct techniquesTechniques
76 techniquesReporting
Research mentioning Latrodectus
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators
Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.
Malware-Traffic-Analysis.net - 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT
ACR Stealer Spreads Through ClickFix Lures
Microsoft reported a rise in ACR Stealer intrusions across customer environments, tracing two prominent infection chains that relied on ClickFix social engineering to trick users into launching malicious commands. In one chain, attackers delivered DLLs over WebDAV, then used obfuscated PowerShell, Python-based loaders, and scheduled tasks for persistence; some infections also resolved command-and-control infrastructure through blockchain-based dead-drop techniques such as EtherHiding. A second chain used mshta.exe, VBScript, and obfuscated PowerShell before retrieving payloads hidden inside a hosted JPEG and executing them filelessly in memory. The campaigns were designed to steal browser credentials, cookies, authentication tokens, and sensitive enterprise documents, including PDFs and Microsoft 365-related files. Microsoft said the malware abuses DPAPI to decrypt browser data and stages the collected information for exfiltration. The company published indicators of compromise, MITRE ATT&CK mappings, hunting queries, and mitigation guidance focused on detecting ClickFix lures, suspicious WebDAV or MSHTA activity, obfuscated PowerShell, persistence mechanisms, and browser credential theft.