Researchers reported that Latrodectus, a Windows downloader increasingly tied to email and phishing campaigns, has expanded across multiple infection chains while showing strong links to IcedID through code similarities, shared infrastructure, and overlapping tradecraft. Threat actors including TA577 and TA578 have distributed it through obfuscated JavaScript, MSI installers, DLLs, ISO and LNK files, WebDAV-hosted payloads, and phishing lures such as fake Google Authenticator downloads; one campaign also paired Latrodectus with ACR Stealer, while another analysis found Brute Ratel C4 Badger used to load the malware. Typical execution flows use JavaScript to invoke msiexec.exe, install a remote MSI, and launch a malicious DLL with rundll32.exe, often via the exported function AnselEnableCheck.
Recent analyses show Latrodectus evolving rapidly as a lightweight loader focused on reconnaissance, persistence, and payload delivery. Newer variants replaced earlier XOR-based string deobfuscation with AES-256 CTR, changed campaign ID inputs, updated RC4-based C2 communications, and switched HTTP endpoints from /live to /test, while adding commands to download and execute shellcode and to write files into %AppData%. The malware also uses anti-analysis checks, scheduled-task persistence, runtime API resolution, and encrypted command traffic, and it retains functionality to fetch IcedID components even when those payloads were not observed. Researchers said the pace of infrastructure turnover and feature changes indicates active development and continued use in financially motivated intrusion campaigns.

Pull IOCs and campaign context straight into your stack.
20 events from the most recent confirmed update back to the earliest known activity.
A report published on 2025-04-02 described a Latrodectus delivery campaign that abused websites vulnerable to CORS and iframe injection to display a fake Cloudflare CAPTCHA page. The chain profiled visitors, sent victim details to the attacker via the Telegram Bot/Chat API, and led Windows users through a clipboard-delivered command sequence that downloaded an MSI package side-loading a Latrodectus DLL.
Netskope disclosed that Latrodectus version 1.4 added command ID 22 to download and execute shellcode while passing a base64 function pointer, and command ID 25 to download a file into the %AppData% directory.
Netskope reported that Latrodectus 1.4 replaced earlier XOR-based string deobfuscation with AES-256 in CTR mode, changed the campaign ID input string to "Wiski," introduced new RC4 keys, and switched its C2 endpoint from "/live" to "/test."
On 29 August 2024, Netskope published analysis of a new Latrodectus payload identified as version 1.4, describing an infection chain using obfuscated JavaScript, an MSI installer, a Dave-crypter-protected DLL, and execution through the export "AnselEnableCheck."
Cyble reported that the analyzed Latrodectus sample was version 1.3, with a new C2 encryption key, a scheduled task changed to run every 10 minutes instead of only at logon, and an expanded command set of 12 commands.
On 8 August 2024, Cyble documented a phishing campaign using googleaauthenticator[.]com and a fake GoogleAuthSetup.exe installer to drop both Latrodectus and ACR Stealer while displaying a deceptive installation error.
In July 2024, researchers observed Latrodectus being delivered by Brute Ratel C4 Badger, showing the malware being used outside the previously emphasized spam-driven chains.
On 16 May 2024, Elastic Security Labs published analysis describing Latrodectus as a lightweight loader increasingly used in email campaigns and a potential replacement for IcedID, while documenting its persistence, anti-analysis, and C2 behavior.
On 4 April 2024, Proofpoint and Team Cymru published research assessing Latrodectus as a distinct malware family likely written by the same developers as IcedID, based on code similarities, infrastructure overlap, and shared operational patterns.
An Embee Research analysis mapped phishing infrastructure associated with a Latrodectus infection chain by pivoting from lufyfeo[.]org through passive DNS and shared HTTP 302 redirects. The research identified 36 domains on 193.106.174[.]218 that redirected to benign-looking PDF URLs on documentcloud[.]org or harvardlawreview[.]org, clustering infrastructure tied to the campaign.
Elastic Security Labs observed increased financially motivated email campaigns delivering Latrodectus beginning in early March 2024, commonly using oversized JavaScript droppers and WebDAV-hosted MSI installers.
On 20 February 2024, TA578 impersonated companies and used website contact forms to send copyright infringement lures containing unique URLs that led to Latrodectus delivery.
Proofpoint identified nearly a dozen campaigns delivering Latrodectus beginning in February 2024, showing increased operational use of the malware in email-driven activity.
Since mid-January 2024, TA578 has distributed Latrodectus almost exclusively in observed email threat campaigns, replacing payloads it had previously favored such as IcedID and Bumblebee.
On 15 December 2023, Proofpoint observed TA578 delivering Latrodectus through a DanaBot infection chain. The report also noted TA578 began using Latrodectus as its initial access payload from December 2023 onward.
On 28 November 2023, TA577 used thread-hijacked emails linking to zipped JavaScript or ISO files that executed Latrodectus via the export "nail."
On 24 November 2023, TA577 sent emails with URLs that downloaded JavaScript, which created BAT files using curl to execute a DLL export named "scab" and launch Latrodectus.
Proofpoint observed TA577 distributing Latrodectus in at least three campaigns in November 2023. The activity marked some of the earliest observed email-based delivery of the malware.
Walmart researchers first reported Latrodectus in October 2023, documenting a loader closely tied to IcedID behavior and infrastructure. Their analysis noted RC4-encrypted C2 traffic, the /live/ endpoint, scheduled-task persistence, and a command to download IcedID's bp.dat component.
Team Cymru identified a Latrodectus Tier 2 backend that was established around August 2023, later linking it to historic IcedID infrastructure and jumpboxes.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 159 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
9 references tracked. Mallory keeps watching after this page renders.
jmp-esp.org
Open sourcenetskope.com
Open sourcenetskope.com
Open sourcecyble.com
Open sourceany.run
Open sourceelastic.co
Open sourceproofpoint.com
Open sourceembeeresearch.io
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.