Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID
Essential information
- Published
- 17/05/2024 09:03
- Modified
- 21/05/2024 09:06
- Tags
- 2024-05-17 cybercrime financially-motivated icedid latrodectus loader malware
- Related entities
- 7 observables, 9 techniques (mitre), 2 malware
Description
LATRODECTUS is a malware loader gaining popularity among cybercriminals, with strong connections to the ICEDID malware family. It offers standard capabilities for deploying payloads and conducting post-exploitation activities. Initially discovered by Walmart researchers in 2023, it continues evolving with new features like process discovery and desktop file listing. LATRODECTUS shares infrastructure and techniques with ICEDID operators, suggesting it may be a potential replacement. Elastic Security provides robust detection capabilities through memory signatures, behavioral rules, and hunting opportunities to respond to threats like LATRODECTUS.