Skip to content

Latrodectus

Latrodectus, also known as IceNova and BlackWidow, is a Windows malware family primarily used as a downloader with backdoor functionality.

Profile source: Mallory opens in a new tab

Latrodectus

Family profile

Latrodectus, also known as IceNova and BlackWidow, is a Windows malware family primarily used as a downloader with backdoor functionality. It emerged in late 2023 and is widely assessed to be associated with the same cybercrime ecosystem behind IcedID, with multiple vendors describing it as a likely successor or replacement within that tooling lineage. The malware is used by financially motivated threat actors and initial-access brokers to establish a foothold, profile infected systems, execute attacker-supplied commands, and retrieve additional payloads for follow-on intrusion activity.

Latrodectus commonly executes as a DLL launched through rundll32 and has been observed in infection chains involving scripts, MSI installers, JavaScript, malicious spam, phishing pages, fake software or security updates, and ClickFix-style social engineering. Campaigns have used financially themed lures, tax-related themes, cloned brand pages, and impersonation of trusted software and services such as Google Authenticator, Google Safety Centre, and security products. It has also been delivered by other malware, including DanaBot, and has appeared alongside Brute Ratel C4 in multi-stage campaigns.

Once active, Latrodectus performs host profiling and reconnaissance, including collection of the current username and broader system metadata such as operating system, architecture, computer name, domain context, uptime, and network configuration. Observed command templates and decrypted strings show support for discovery of domain trusts, network views, workstation configuration, group membership, and antivirus products, including enumeration of privileged domain groups. The malware communicates with command-and-control infrastructure over HTTP or HTTPS, including encoded POST-based exchanges, and exfiltrates encrypted system information to register and manage infected hosts.

Latrodectus includes anti-analysis and defense-evasion features such as custom string obfuscation and environment checks intended to identify sandboxed systems. It has also been observed establishing persistence through Windows scheduled tasks created via COM. The malware supports arbitrary command execution and staged delivery of additional DLL or EXE payloads, making it a flexible access platform rather than a single-purpose implant.

Operationally, Latrodectus has been used to deliver or facilitate deployment of additional malware including IcedID, Brute Ratel C4, and BackConnect or VNC-style modules that enable hands-on-keyboard access. Its presence is therefore often a precursor to broader post-compromise activity. Victimology and tradecraft observed to date align most strongly with financially motivated cybercrime operations rather than nation-state activity.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Reconnaissance

Reported operators

Threat actors

11 named in public reporting
TA578

On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.

TA571

On 20 September 2024, Proofpoint researchers identified a campaign delivering Brute Ratel C4 and Latrodectus.

TA577

Latrodectus is a downloader used by adversaries to execute arbitrary commands and deliver additional payloads, frequently leveraging financially-themed lures.

Storm-0249

Latrodectus is a downloader used by adversaries to execute arbitrary commands and deliver additional payloads, frequently leveraging financially-themed lures.

WIZARD SPIDER

Latrodectus, also known as IceNova Backdoor ... is a family of malware that has been observed lately in campaigns linked to groups such as Trickbot ( WIZARD SPIDER ) and Conti (and potentially, in Ransomware deliveries), in addition to being attributed to developers from IcedID . Therefore, Latrodectus has been highlighted as a potential threat and is used as a Loader for other malware.

Conti

Latrodectus, also known as IceNova Backdoor ... is a family of malware that has been observed lately in campaigns linked to groups such as Trickbot ( WIZARD SPIDER ) and Conti (and potentially, in Ransomware deliveries), in addition to being attributed to developers from IcedID . Therefore, Latrodectus has been highlighted as a potential threat and is used as a Loader for other malware.

Trickbot

Latrodectus, also known as IceNova Backdoor ... is a family of malware that has been observed lately in campaigns linked to groups such as Trickbot ( WIZARD SPIDER ) and Conti (and potentially, in Ransomware deliveries), in addition to being attributed to developers from IcedID . Therefore, Latrodectus has been highlighted as a potential threat and is used as a Loader for other malware.

unit_42

The tweet details a Latrodectus infection leveraging phishing links to redirect victims to a javascript file, which ultimately loads LummaStealer Malware.

Lunar Spider

LUNAR SPIDER’s recent campaign used Latrodectus, a heavily obfuscated JavaScript loader, to deliver Brute Ratel C4 payloads targeting the financial sector.

Water Curupira

Bumblebee and Latrodectus, which are both malware loaders, are designed to steal personal data, along with downloading and executing additional payloads onto compromised hosts.

Rhysida

In addition to OysterLoader, Expel discovered the Rhysida threat actors were also using Latrodectus malware in its campaign...

Exploited software

Vulnerabilities linked to Latrodectus

1 CVEs

MITRE ATT&CK

Latrodectus in ATT&CK

76 distinct techniques

Techniques

76 techniques
T1036.005 Match Legitimate Resource Name or Location T1497.001 System Checks T1053.005 Scheduled Task T1027 Obfuscated Files or Information T1071.001 Web Protocols T1566 Phishing T1105 Ingress Tool Transfer T1218.011 Rundll32 T1218 System Binary Proxy Execution T1083 File and Directory Discovery T1204.002 Malicious File T1041 Exfiltration Over C2 Channel T1016 System Network Configuration Discovery T1087.002 Domain Account T1033 System Owner/User Discovery T1140 Deobfuscate/Decode Files or Information T1069.002 Domain Groups T1059 Command and Scripting Interpreter T1059.001 PowerShell T1218.007 Msiexec T1204 User Execution T1566.001 Spearphishing Attachment T1082 System Information Discovery T1566.002 Spearphishing Link T1059.007 JavaScript T1055 Process Injection T1608.001 Upload Malware T1070.004 File Deletion T1566.003 Spearphishing via Service T1132 Data Encoding T1071 Application Layer Protocol T1547.001 Registry Run Keys / Startup Folder T1112 Modify Registry T1005 Data from Local System T1059.003 Windows Command Shell T1057 Process Discovery T1036 Masquerading T1047 Windows Management Instrumentation T1070 Indicator Removal T1219 Remote Access Tools T1497 Virtualization/Sandbox Evasion T1622 Debugger Evasion T1027.007 Dynamic API Resolution T1189 Drive-by Compromise T1127 Trusted Developer Utilities Proxy Execution T1553.002 Code Signing T1027.002 Software Packing T1027.013 Encrypted/Encoded File T1053 Scheduled Task/Job T1608.006 SEO Poisoning T1583 Acquire Infrastructure T1620 Reflective Code Loading T1021.002 SMB/Windows Admin Shares T1106 Native API T1583.006 Web Services T1087 Account Discovery T1529 System Shutdown/Reboot T1102 Web Service T1027.001 Binary Padding T1104 Multi-Stage Channels T1482 Domain Trust Discovery T1518.001 Security Software Discovery T1135 Network Share Discovery T1573.001 Symmetric Cryptography T1021.005 VNC T1564.004 NTFS File Attributes T1204.001 Malicious Link T1132.001 Standard Encoding T1559.001 Component Object Model T1090 Proxy T1012 Query Registry T1583.008 Malvertising T1574.001 DLL T1018 Remote System Discovery T1069 Permission Groups Discovery T1562.001 Disable or Modify Tools

Reporting

Research mentioning Latrodectus

Jul 31
Malware News

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft - Malware News - Malware Analysis, News and Indicators

Microsoft reported that social-engineering lures are increasingly being used to trick users into launching malware themselves, with the ClickFix technique emerging as a major delivery method across phishing, malvertising, and compromised websites. In ClickFix attacks, victims are shown fake CAPTCHA, verification, or repair prompts that copy malicious commands to the clipboard and persuade them to run them, often leading to fileless execution through LOLBins, obfuscated PowerShell, and follow-on payloads such as Lumma Stealer, DarkGate, Latrodectus, ScreenConnect, and AMOS. Microsoft said the technique has hit thousands of enterprise and consumer devices daily and is now supported by a growing underground market of ClickFix builder kits sold on criminal forums. Fresh activity shows the tactic continuing to evolve. A SmartApeSG campaign observed on compromised web traffic redirected victims to a fake human-verification flow that fetched an HTA downloader from deltaode[.]com, retrieved a ZIP archive, and abused DLL side-loading to launch an unidentified RAT that later communicated with 89.124.79[.]98 over TCP 443. Separately, Microsoft linked the CaptiveCrunch campaign to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard, which has manipulated DNS and HTTP traffic on hospitality and other captive-portal networks to redirect travelers to phishing pages and fake browser or OS updates delivering CornFlake and ChocoShell for credential theft and espionage, including theft of browser credentials, Microsoft 365 tokens, and Wi-Fi credentials.

Jul 31
Malware Traffic Analysis

Malware-Traffic-Analysis.net - 2026-07-31: SmartApeSG ClickFix campaign pushes unidentified RAT

Jul 24
Security Online Info

ACR Stealer Spreads Through ClickFix Lures

Microsoft reported a rise in ACR Stealer intrusions across customer environments, tracing two prominent infection chains that relied on ClickFix social engineering to trick users into launching malicious commands. In one chain, attackers delivered DLLs over WebDAV, then used obfuscated PowerShell, Python-based loaders, and scheduled tasks for persistence; some infections also resolved command-and-control infrastructure through blockchain-based dead-drop techniques such as EtherHiding. A second chain used mshta.exe, VBScript, and obfuscated PowerShell before retrieving payloads hidden inside a hosted JPEG and executing them filelessly in memory. The campaigns were designed to steal browser credentials, cookies, authentication tokens, and sensitive enterprise documents, including PDFs and Microsoft 365-related files. Microsoft said the malware abuses DPAPI to decrypt browser data and stages the collected information for exfiltration. The company published indicators of compromise, MITRE ATT&CK mappings, hunting queries, and mitigation guidance focused on detecting ClickFix lures, suspicious WebDAV or MSHTA activity, obfuscated PowerShell, persistence mechanisms, and browser credential theft.

Jul 18
Bleeping Computer

Microsoft warns of surge in ACR Stealer attacks on customers

Jul 17
Scworld

ACR Stealer exploits user interaction to steal sensitive data | brief | SC Media

Jul 17
The Hacker News

ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files

Jul 17
Trojan Killer News

ACR Stealer ClickFix Campaign Uses WebDAV and MSHTA

Jul 16
Malware News

ACR Stealer: Two observed intrusion chains amid increased threat activity - Malware News - Malware Analysis, News and Indicators

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.