Bumblebee and Latrodectus Malware Return with Sophisticated Phishing Strategies
Oct 22, 2024
Malware / Threat Intelligence
 Two malware families that suffered setbacks in the aftermath of a coordinated law enforcement operation called Endgame  have resurfaced as part of new phishing campaigns.  Bumblebee  and Latrodectus , which are both malware loaders, are designed to steal personal data, along with downloading and executing additional payloads onto compromised hosts.  Tracked under the names BlackWidow, IceNova, Lotus, or Unidentified 111, Latrodectus, is also considered to be a successor to IcedID  owing to infrastructure overlaps between the two malware families. It has been used in campaigns associated with two initial access brokers (IABs) known as TA577 (aka Water Curupira) and TA578.  In May 2024, a coalition of European countries said it dismantled  over 100 servers linked to several malware strains such as IcedID (and, by extension, Latrodectus), SystemBC, PikaBot, SmokeLoader, Bumblebee, and TrickBot.   "Although Latrodectus was not mentioned in the operation, it was also affected and its ...