Latrodectus Malware
Summary
Latrodectus stands out as an emerging downloader equipped with diverse sandbox evasion capabilities, meticulously crafted to fetch payloads and execute arbitrary commands. TA578, a known actor since at least May 2020, has been associated with various email campaigns distributing Ursnif, IcedID, KPOT Stealer, Buer Loader, BazaLoader, Cobalt Strike, and Bumblebee. The attack sequences involve exploiting website contact forms to send legal threats regarding purported copyright violations to targeted organizations. Embedded links within these messages redirect recipients to deceptive websites, prompting them to download a JavaScript file responsible for initiating the primary payload via msiexec. Similar to IcedID, Latrodectus is programmed to transmit registration details via a POST request to the C2 server, where the fields are concatenated into HTTP parameters and encrypted.