Skip to content

Latrodectus

Latrodectus, also known as IceNova and BlackWidow, is a Windows malware loader with backdoor functionality first identified in late 2023.

Profile source: Mallory opens in a new tab

Latrodectus

Family profile

Latrodectus, also known as IceNova and BlackWidow, is a Windows malware loader with backdoor functionality first identified in late 2023. It is used in financially motivated intrusion chains to profile compromised hosts, receive attacker commands, establish scheduled-task persistence, and download and execute follow-on payloads. Observed payload delivery includes PE files, DLLs launched through Rundll32, in-memory shellcode, IcedID components, information stealers, Brute Ratel C4, and VNC-style remote-access modules. Latrodectus performs detailed host, domain, process, network, file, and security-software reconnaissance and transmits collected host and campaign data to its command-and-control infrastructure. It incorporates anti-analysis and defense-evasion measures including debugger, sandbox, process-count, operating-system, network-adapter, and virtualization-related checks; runtime API resolution; string encryption; packing; masquerading; and self-deletion through NTFS alternate data streams. It has been observed using encrypted web-based command-and-control and can update or terminate itself. Delivery commonly occurs through phishing and spam campaigns using malicious attachments, links, JavaScript, and MSI-based execution chains; it has also been delivered through malicious advertising, compromised-site watering holes, and fake verification lures that induce user execution. TA577 and TA578 have distributed Latrodectus. Multiple security vendors assess it to have a development or operational relationship with the IcedID ecosystem, though the precise relationship is not conclusively established.

Capabilities

  • Defense Evasion
  • Dll Sideloading
  • Exfiltration
  • Initial Access
  • Persistence
  • Post Exploitation
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 17, 2026
Last activity
Sep 20, 2026
Feed role
C2
Host form
0 IP / 5 hostnames

Leading locations

  • US4
  • NL1

Leading providers

  • Amazon.com, Inc.3
  • Amazon.com, Inc.1
  • Omegatech LTD1

Infrastructure traits

  • Hosting 5

Samples

Recent associated samples

Reported operators

Threat actors

11 named in public reporting
TA578

TA578 is a threat actor that has used contact forms and email to initiate communications with victims and to distribute malware including Latrodectus, IcedID, and Bumblebee.

TA577

Latrodectus is a downloader first discovered by Walmart back in October of 2023... During the Threat Labs hunting activities we discovered a new version of the Latrodectus payload, version 1.4.

Storm-0249

Latrodectus is a loader primarily used for initial access and payload delivery. It features dynamic command-and-control (C2) configurations, anti-analysis features such as minimum process count and network adapter check, C2 check-in behavior that splits POST data between the Cookie header and POST data.

Unit 42

2024-03-07 (THURSDAY): LATRODECTUS INFECTION LEADS TO LUMMA STEALER

TA571

On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.

WIZARD SPIDER

Latrodectus, also known as IceNova Backdoor ... is a family of malware that has been observed lately in campaigns linked to groups such as Trickbot ( WIZARD SPIDER ) and Conti (and potentially, in Ransomware deliveries), in addition to being attributed to developers from IcedID . Therefore, Latrodectus has been highlighted as a potential threat and is used as a Loader for other malware.

Conti

Latrodectus, also known as IceNova Backdoor ... is a family of malware that has been observed lately in campaigns linked to groups such as Trickbot ( WIZARD SPIDER ) and Conti (and potentially, in Ransomware deliveries), in addition to being attributed to developers from IcedID . Therefore, Latrodectus has been highlighted as a potential threat and is used as a Loader for other malware.

Trickbot

Latrodectus, also known as IceNova Backdoor ... is a family of malware that has been observed lately in campaigns linked to groups such as Trickbot ( WIZARD SPIDER ) and Conti (and potentially, in Ransomware deliveries), in addition to being attributed to developers from IcedID . Therefore, Latrodectus has been highlighted as a potential threat and is used as a Loader for other malware.

Lunar Spider

LUNAR SPIDER’s recent campaign used Latrodectus, a heavily obfuscated JavaScript loader, to deliver Brute Ratel C4 payloads targeting the financial sector.

Water Curupira

Bumblebee and Latrodectus, which are both malware loaders, are designed to steal personal data, along with downloading and executing additional payloads onto compromised hosts.

Rhysida

In addition to OysterLoader, Expel discovered the Rhysida threat actors were also using Latrodectus malware in its campaign...

Exploited software

Vulnerabilities linked to Latrodectus

1 CVEs

MITRE ATT&CK

Latrodectus in ATT&CK

84 distinct techniques

Techniques

84 techniques
T1027.007 Dynamic API Resolution T1083 File and Directory Discovery T1218.011 Rundll32 T1482 Domain Trust Discovery T1057 Process Discovery T1518.001 Security Software Discovery T1018 Remote System Discovery T1016 System Network Configuration Discovery T1573.001 Symmetric Cryptography T1497 Virtualization/Sandbox Evasion T1053.005 Scheduled Task T1070.004 File Deletion T1055 Process Injection T1069.002 Domain Groups T1105 Ingress Tool Transfer T1622 Debugger Evasion T1564.004 NTFS File Attributes T1566.001 Spearphishing Attachment T1059.003 Windows Command Shell T1027 Obfuscated Files or Information T1218.007 Msiexec T1047 Windows Management Instrumentation T1036 Masquerading T1082 System Information Discovery T1071.001 Web Protocols T1189 Drive-by Compromise T1059.001 PowerShell T1115 Clipboard Data T1071 Application Layer Protocol T1204 User Execution T1190 Exploit Public-Facing Application T1204.002 Malicious File T1566.002 Spearphishing Link T1059.007 JavaScript T1027.002 Software Packing T1129 Shared Modules T1566 Phishing T1001 Data Obfuscation T1566.003 Spearphishing via Service T1059 Command and Scripting Interpreter T1106 Native API T1560.001 Archive via Utility T1620 Reflective Code Loading T1218 System Binary Proxy Execution T1140 Deobfuscate/Decode Files or Information T1486 Data Encrypted for Impact T1029 Scheduled Transfer T1564 Hide Artifacts T1036.005 Match Legitimate Resource Name or Location T1497.001 System Checks T1041 Exfiltration Over C2 Channel T1087.002 Domain Account T1033 System Owner/User Discovery T1608.001 Upload Malware T1132 Data Encoding T1547.001 Registry Run Keys / Startup Folder T1112 Modify Registry T1005 Data from Local System T1070 Indicator Removal T1219 Remote Access Tools T1127 Trusted Developer Utilities Proxy Execution T1553.002 Code Signing T1027.013 Encrypted/Encoded File T1053 Scheduled Task/Job T1608.006 SEO Poisoning T1583 Acquire Infrastructure T1021.002 SMB/Windows Admin Shares T1583.006 Web Services T1087 Account Discovery T1529 System Shutdown/Reboot T1102 Web Service T1027.001 Binary Padding T1104 Multi-Stage Channels T1135 Network Share Discovery T1021.005 VNC T1204.001 Malicious Link T1132.001 Standard Encoding T1559.001 Component Object Model T1090 Proxy T1012 Query Registry T1583.008 Malvertising T1574.001 DLL T1069 Permission Groups Discovery T1562.001 Disable or Modify Tools

Reporting

Research mentioning Latrodectus

Aug 11
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.

Jul 31
Malware News

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators

Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.

Jul 31
Malware Traffic Analysis

Malware-Traffic-Analysis.net - 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

Jul 24
Security Online Info

ACR Stealer Spreads Through ClickFix Lures

Microsoft reported a rise in ACR Stealer intrusions across customer environments, tracing two prominent infection chains that relied on ClickFix social engineering to trick users into launching malicious commands. In one chain, attackers delivered DLLs over WebDAV, then used obfuscated PowerShell, Python-based loaders, and scheduled tasks for persistence; some infections also resolved command-and-control infrastructure through blockchain-based dead-drop techniques such as EtherHiding. A second chain used mshta.exe, VBScript, and obfuscated PowerShell before retrieving payloads hidden inside a hosted JPEG and executing them filelessly in memory. The campaigns were designed to steal browser credentials, cookies, authentication tokens, and sensitive enterprise documents, including PDFs and Microsoft 365-related files. Microsoft said the malware abuses DPAPI to decrypt browser data and stages the collected information for exfiltration. The company published indicators of compromise, MITRE ATT&CK mappings, hunting queries, and mitigation guidance focused on detecting ClickFix lures, suspicious WebDAV or MSHTA activity, obfuscated PowerShell, persistence mechanisms, and browser credential theft.

Jul 18
Bleeping Computer

Microsoft warns of surge in ACR Stealer attacks on customers

Jul 17
Scworld

ACR Stealer exploits user interaction to steal sensitive data | brief | SC Media

Jul 17
The Hacker News

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

Jul 17
Trojan Killer News

ACR Stealer ClickFix Campaign Uses WebDAV and MSHTA

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.