Latrodectus Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
November 3, 2025
Last Seen
April 22, 2026

Latrodectus is a malware family tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity April 22, 2026.

Overview

Latrodectus is a ransomware family observed in recent campaigns associated with the Rhysida threat group. The operation uses malvertising to deliver payloads to users on Teams, Zoom, and PuTTY, and abuses a Microsoft code-signing certificate to bypass defenses, enabling stealthy execution and encryption. This combination of delivery and evasion highlights the evolving capabilities of contemporary ransomware campaigns.

Related Threat Clusters

Recent Intelligence Reports

  • T1005 — attack.mitre.org · April 22, 2026
  • Rhysida gang now malvertising to people on Teams, Zoom, and PutTy — Cybernews · November 4, 2025
  • Rhysida ransomware exploits Microsoft certificate to slip malware past defenses — Csoonline · November 3, 2025

CVSS v3.1 Breakdown