Latrodectus Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
November 3, 2025
Last Seen
July 23, 2026

Latrodectus is a ransomware family observed in recent campaigns associated with the Rhysida threat group.

Overview

Latrodectus is a ransomware family observed in recent campaigns associated with the Rhysida threat group. The operation uses malvertising to deliver payloads to users on Teams, Zoom, and PuTTY, and abuses a Microsoft code-signing certificate to bypass defenses, enabling stealthy execution and encryption. This combination of delivery and evasion highlights the evolving capabilities of contemporary ransomware campaigns.

Related Threat Clusters

Recent Intelligence Reports

  • T1102 — attack.mitre.org · July 23, 2026
  • 001 — attack.mitre.org · July 23, 2026
  • T1005 — attack.mitre.org · April 22, 2026
  • Rhysida gang now malvertising to people on Teams, Zoom, and PutTy — Cybernews · November 4, 2025
  • Rhysida ransomware exploits Microsoft certificate to slip malware past defenses — Csoonline · November 3, 2025

CVSS v3.1 Breakdown