Threats Tagged 'latrodectus'
View all threats tagged with 'latrodectus'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'latrodectus'
Click on any threat for detailed analysis and mitigation recommendations
The report details a malware attack on a large Polish organization involving fake CAPTCHA techniques. It describes the initial infection vector, where users were tricked into running malicious code through a Windows+R shortcut. The analysis covers two main malware families: Latrodectus (version 2.3) and Supper. The report provides technical details on the malware's functionality, communication protocols, and persistence mechanisms. It also includes indicators of compromise, such as C2 server IP addresses and file hashes. The authors emphasize the importance of employee education and monitoring for unusual events to mitigate such threats. Join the discussion | AlienVault OTX General | 02/19/2026, 15:26:28 UTC Added: 02/19/2026, 18:01:12 UTC |
The German hosting provider aurologic GmbH has become a critical infrastructure hub for multiple high-risk and sanctioned cybercrime networks, including entities involved in disinformation and malware campaigns. Despite public scrutiny and sanctions, aurologic continues to provide upstream transit services, enabling threat actors to maintain operational stability. The provider's approach to abuse handling is reactive and legally compliant rather than proactive, allowing malicious infrastructure to persist. This situation highlights challenges in accountability within the hosting ecosystem and the risks posed by infrastructure neutrality when it enables cybercrime. Numerous suspicious domains linked to aurologic-hosted networks have been identified, associated with malware families and threat actor tools. European organizations, especially in Germany, face increased risks due to this infrastructure's stability and continued operation. Mitigation requires enhanced monitoring of traffic from these domains, collaboration with upstream providers, and pressure on hosting providers to adopt proactive abuse prevention. Countries with significant internet infrastructure and cybercrime targets in Europe are most likely to be affected. Join the discussion | AlienVault OTX General | 11/06/2025, 18:51:59 UTC Added: 11/06/2025, 20:20:40 UTC |
The Rhysida ransomware gang, previously known as Vice Society, is conducting a sophisticated malvertising campaign using Bing ads to distribute OysterLoader malware. This malware acts as an initial access tool, establishing persistence and enabling further payload deployment, including ransomware. The gang employs code-signing certificates, including Microsoft Trusted Signing, to evade detection and increase trustworthiness of their malware. Their activity has notably increased in 2025, with over 40 certificates tracked compared to 7 in 2024. They also utilize Latrodectus malware for initial access. The campaign leverages legitimate services and advanced evasion techniques, highlighting significant resource investment and operational maturity. This threat poses a medium severity risk but can lead to severe consequences if ransomware is deployed. European organizations should be vigilant against malvertising campaigns and suspicious software downloads, especially those impersonating popular software. Mitigation requires enhanced monitoring of code-signed binaries, user awareness, and blocking malicious ad traffic. Join the discussion | AlienVault OTX General | 11/03/2025, 10:15:39 UTC Added: 11/03/2025, 10:56:13 UTC |
The ClickFix social engineering technique has gained popularity among threat actors, targeting thousands of devices globally. It tricks users into executing malicious commands on their devices by exploiting their tendency to solve minor technical issues. The technique often impersonates legitimate brands and combines with delivery vectors like phishing and malvertising. ClickFix campaigns typically lead users to a visual lure, such as a landing page, instructing them to run commands in the Windows Run dialog. This user interaction element helps bypass conventional security solutions. Various malware, including infostealers and remote access tools, are delivered through ClickFix attacks. The technique has evolved to target macOS users and is being sold as part of malware kits on hacker forums. Join the discussion | AlienVault OTX General | 08/21/2025, 21:03:25 UTC Added: 08/21/2025, 21:17:47 UTC |
This article discusses the rising threat of ClickFix, a social engineering technique used by threat actors to trick victims into executing malicious commands under the guise of quick fixes for computer issues. The technique has been observed in campaigns distributing various malware, including NetSupport RAT, Latrodectus, and Lumma Stealer. ClickFix lures often use clipboard hijacking and can bypass standard detection controls. The article provides case studies of recent campaigns, hunting tips for detecting ClickFix infections, and recommendations for proactive defense measures. It emphasizes the importance of user education and implementing robust security controls to mitigate this evolving threat. Join the discussion | AlienVault OTX General | 07/10/2025, 17:53:19 UTC Added: 07/10/2025, 18:31:06 UTC |
Showing 1 to 5 of 5 results