Latrodectus is a malware family tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 3, 2025; most recent activity April 22, 2026.
Latrodectus is a ransomware family observed in recent campaigns associated with the Rhysida threat group. The operation uses malvertising to deliver payloads to users on Teams, Zoom, and PuTTY, and abuses a Microsoft code-signing certificate to bypass defenses, enabling stealthy execution and encryption. This combination of delivery and evasion highlights the evolving capabilities of contemporary ransomware campaigns.
Recent reports detail the tactics employed by various cyber adversaries to enumerate files and directories on compromised systems. Adversaries utilize command shell utilities and custom tools to gather sensitive…
Ransomware actors are increasingly focusing on cloud-based assets, particularly in AWS environments. This shift involves utilizing various tactics to compromise critical business data, moving away from traditional…
The Rhysida ransomware group is exploiting fake advertisements for Microsoft Teams to distribute malware, specifically targeting users searching for the software. This campaign employs malvertising techniques,…