Following reports of the return of Bumblebee, another malware loader appears to have resurfaced in phishing attacks: Latrodectus. The infrastructure of both malware was taken down as part of the police operation Endgamein May. However, both have resurfaced in new phishing campaigns.

The Bumblebee and Latrodectus loaders are designed to steal personal data and download and execute additional malicious payloads on compromised machines.
Latrodectus, also known as BlackWidow, IceNova, Lotus or Unidentified 111, is considered a successor to the IcedID malware, due to shared infrastructure elements. It has been used in campaigns associated with two initial access brokers (IABs) known as TA577 (or Water Curupira) and TA578.
See also: Hackers distribute Wiper Malware to Israeli organizations
In May 2024, a coalition of European countries, led by Europol, said it had destroyed more than 100 servers associated with various malware strains such as IcedID (and by extension Latrodectus), SystemBC, PikaBot, SmokeLoader, Bumblebee, and TrickBot.
“ Although Latrodectus was not reported to the business, it was also affected and its infrastructure went offline ,” Bitsight security researcher João Batista had said .
Cybersecurity firm Trustwave, however, described Latrodectus as a “distinct threat” that has received a boost after Operation Endgame.
“While initially affected, Latrodectus quickly recovered. Its advanced capabilities filled the gap left by similar malware and made it a formidable threat,” the company said.
Attacks typically involve malicious emails/messages, exploit existing email threads, and impersonate legitimate entities, such as Microsoft Azure and Google Cloud, to trigger the malware deployment process.
In the most recent attacks, malicious emails (themed as DocuSign) have embedded PDF documents containing a malicious link or HTML files with embedded JavaScript code. These are designed to download an MSI installer and a PowerShell script, respectively.
See also: New ClickFix attack: Fake Google Meet errors distribute malware
Regardless of the method used, the attack culminates in the deployment of a malicious DLL file, which launches the Latrodectus malware.
“Latrodectus leverages legacy infrastructure, combined with a new, innovative method of malware payload distribution. It primarily targets financial services, automotive, and enterprise,” said Forcepoint researcher Mayur Sewani.
The ongoing Latrodectus campaigns are combined with the return of the Bumblebee loader. In the new attacks observed by Netskope, the Bumblebee infection likely begins with a phishing email that lures the victim into downloading a ZIP file and extracting and executing the file within it.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The ZIP file contains a file LNK named “Report-41952.lnk”. Once executed, it starts various processes to download and execute the final Bumblebee payload into memory.

Protection
The above shows that a series of measures are necessary to protect against Latrodectus and Bumblebee malware. First, it is important to keep updated operating systems and applications, as these updates often include security fixes that can protect devices from such attacks.
Second, it is recommended to use strong, unique passwords. This can help protect accounts from being hacked.
See also: ScarCruft spreads RokRAT malware via Windows Zero-Day
Third, educating users about the dangers of malware is essential. Users should know the signs of suspicious emails and avoid clicking on suspicious links.
Finally, the need for using security solutions that provide real-time protection and have the ability to detect and remove malware is emphasized.
Source: thehackernews.com
