HomeSecurityLatrodectus Malware Loader: The successor to IcedID in phishing campaigns

Latrodectus Malware Loader: The successor to IcedID in phishing campaigns

Cybersecurity researchers have noticed an increase in phishing campaigns since early March 2024. These campaigns are spreading Latrodectus, a new malware loader that is considered the successor to IcedID.

Latrodectus

These campaigns often involve an infection chain with large JavaScript files that leverage WMI's ability to call msiexec.exe and install a remote MSI file hosted on a WEBDAV share, Elastic Security Labs researchers Daniel Stepanic and Samir Bse reported.

See more: New Zoom Phishing campaign threatens employees with dismissal

Latrodectus has features commonly found in malware designed to deploy additional payloads such as QakBot, DarkGate, and PikaBot. This allows hackers to carry out a variety of activities after exploitation.

An analysis of the most recent Latrodectus artifacts revealed an extensive focus on enumeration and execution, as well as the integration of an advanced self-deletion technique to delete executable files.

Malware not only disguises itself as libraries linked to legitimate software, but also uses source code obfuscation techniques and performs anti-analysis checks to prevent it from running in debug or sandbox environments.

Latrodectus enhances its persistence on Windows through a scheduled task and maintains contact with a command and control (C2) server over HTTPS. This allows it to receive commands to gather system information, update, reboot or shut down, and execute shellcode, DLLs, and executables.

Two new commands have been added to the malware since its appearance late last year. These include the ability to list files on the desktop and retrieve the full source of the running process from the infected machine.

It also supports a command to download and execute IcedID (command 18) from the C2 server, although Elastic said it did not observe this behavior in real-world conditions.

"There is definitely a development collaboration or working agreement between IcedID and Latrodectus," the researchers said.

One hypothesis being explored is that LATRODECTUS is being actively developed as a replacement for IcedID, and the handler (#18) was included until malware creators were satisfied with Latrodectus' capabilities.

The development comes as Forcepoint analyzed a phishing campaign that uses invoice-themed email lures to deliver the DarkGate malware.

Read more: CryptoChameleon phishing: Hackers impersonate LastPass employees

The attack chain begins with phishing emails posing as QuickBooks invoices, urging users to install Java by clicking on an embedded link that leads to a malicious Java archive (JAR). The JAR file acts as a conduit for executing a PowerShell script that is responsible for downloading and launching DarkGate via an AutoIT script.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Social engineering campaigns have also used an upgraded version of the phishing-as-a-service (PhaaS) platform called Tycoon to collect Microsoft 365 and Gmail session cookies , as well as bypass multi-factor authentication (MFA).

“This new version features improved evasion capabilities that make it even more difficult for security systems to identify and block the kit,” Proofpoint said. “Significant changes have been implemented to the kit’s JavaScript and HTML code to increase its stealth and effectiveness.”

These include obfuscation techniques to make the source code more understandable and the use of dynamic code generation to modify the code each time it is executed, thus avoiding signature-based detection systems.

Other social engineering detected in March 2024 exploited Google ads impersonating Calendly and Rufus to spread another malware loader known as D3F@ck Loader, which first appeared on cybercrime forums in January 2024 and eventually took down Raccoon Stealer and DanaBat.

“The D3F@ck Loader case shows how malware as a service (MaaS) continues to evolve, using [Extended Validation] certificates to bypass trusted security measures,” cybersecurity firm eSentire noted late last month.

Latrodectus malware phishing campaigns

The revelation comes after the emergence of new malware families, including Fletchen Stealer, WaveStealer, zEus Stealer, and Ziraat Stealer. At the same time, the trojan (RAT) has been detected using the PrivateLoader module to enhance its capabilities.

Read also: Hacker claims to have stolen Samco account data

“By installing VB scripts, modifying the registry, and configuring services to restart the malware at variable times or upon inspection, the [Remcos] malware can fully infiltrate a system and remain undetected,” said SonicWall Capture Labs threat research team

Source: thehackernews

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS