HomeSecurityLatrodectus malware is back - New phishing attacks

Latrodectus malware is back – New phishing attacks

Following reports of the return of Bumblebee, another malware loader appears to have resurfaced in phishing attacks: Latrodectus. The infrastructure of both malware was taken down as part of the police operation Endgamein May. However, both have resurfaced in new phishing campaigns.

Latrodectus malware phishing

The Bumblebee and Latrodectus loaders are designed to steal personal data and download and execute additional malicious payloads on compromised machines.

Latrodectus, also known as BlackWidow, IceNova, Lotus or Unidentified 111, is considered a successor to the IcedID malware, due to shared infrastructure elements. It has been used in campaigns associated with two initial access brokers (IABs) known as TA577 (or Water Curupira) and TA578.

See also: Hackers distribute Wiper Malware to Israeli organizations

In May 2024, a coalition of European countries, led by Europol, said it had destroyed more than 100 servers associated with various malware strains such as IcedID (and by extension Latrodectus), SystemBC, PikaBot, SmokeLoader, Bumblebee, and TrickBot.

“ Although Latrodectus was not reported to the business, it was also affected and its infrastructure went offline ,” Bitsight security researcher João Batista had said .

Cybersecurity firm Trustwave, however, described Latrodectus as a “distinct threat” that has received a boost after Operation Endgame.

“While initially affected, Latrodectus quickly recovered. Its advanced capabilities filled the gap left by similar malware and made it a formidable threat,” the company said.

Attacks typically involve malicious emails/messages, exploit existing email threads, and impersonate legitimate entities, such as Microsoft Azure and Google Cloud, to trigger the malware deployment process.

In the most recent attacks, malicious emails (themed as DocuSign) have embedded PDF documents containing a malicious link or HTML files with embedded JavaScript code. These are designed to download an MSI installer and a PowerShell script, respectively.

See also: New ClickFix attack: Fake Google Meet errors distribute malware

Regardless of the method used, the attack culminates in the deployment of a malicious DLL file, which launches the Latrodectus malware.

“Latrodectus leverages legacy infrastructure, combined with a new, innovative method of malware payload distribution. It primarily targets financial services, automotive, and enterprise,” said Forcepoint researcher Mayur Sewani.

The ongoing Latrodectus campaigns are combined with the return of the Bumblebee loader. In the new attacks observed by Netskope, the Bumblebee infection likely begins with a phishing email that lures the victim into downloading a ZIP file and extracting and executing the file within it.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The ZIP file contains a file LNK named “Report-41952.lnk”. Once executed, it starts various processes to download and execute the final Bumblebee payload into memory.

Latrodectus malware is back - New phishing attacks

Protection

The above shows that a series of measures are necessary to protect against Latrodectus and Bumblebee malware. First, it is important to keep updated operating systems and applications, as these updates often include security fixes that can protect devices from such attacks.

Second, it is recommended to use strong, unique passwords. This can help protect accounts from being hacked.

See also: ScarCruft spreads RokRAT malware via Windows Zero-Day

Third, educating users about the dangers of malware is essential. Users should know the signs of suspicious emails and avoid clicking on suspicious links.

Finally, the need for using security solutions that provide real-time protection and have the ability to detect and remove malware is emphasized.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS