Latrodectus Malware Loader Emerges as IcedID’s Successor in Phishing Campaigns
Beginning in early March 2024, cybersecurity researchers have noticed an increase in email phishing efforts that distribute Latrodectus, a newly developed malware loader that is thought to be the IcedID virus's successor.
Researchers Daniel Stepanic and Samir Bousseaden of Elastic Security Labs stated that "these campaigns usually involve a recognizable infection chain involving oversized JavaScript files that utilize WMI's ability to invoke msiexec.exe and install a remotely-hosted MSI file, remotely hosted on a WEBDAV share."
Latrodectus has the usual features one would anticipate from malware that is meant to release extra payloads like QakBot, DarkGate, and PikaBot, enabling threat actors to carry out a range of post-exploitation operations.
A thorough examination of the most...


