```html ```
top of page

Threat Brief: February 5, 2026 - Latrodectus C2 Infrastructure Surge

  • Writer: Patrick Duggan
    Patrick Duggan
  • Feb 5
  • 3 min read

Updated: Aug 11

# Threat Brief: February 5, 2026 - Latrodectus C2 Infrastructure Surge


**TL;DR:** Pattern 55.3 C2 Hunter detected a surge in Latrodectus loader infrastructure - 4 of the top 5 critical C2 candidates are Latrodectus servers with identical certificate fingerprints. Also found: Kimsuky (North Korea), Cobalt Strike, Havoc, and Sliver C2s. 20 new IOCs indexed.




Priority 1: Latrodectus Campaign Active



**Status:** ACTIVE C2 INFRASTRUCTURE


Latrodectus (aka IceID successor) is staging infrastructure with a distinctive certificate pattern:


**Certificate Fingerprint:**




This is the OpenSSL default template - lazy operators spinning up C2s fast.


**Critical Latrodectus C2s:**

| IP | Score | Cert Flags |

|----|-------|------------|

| 93.116.248.13 | **105** | Self-signed, DGA, expired, default template |

| 104.238.205.20 | 90 | Self-signed, DGA, default template |

| 109.202.111.2 | 90 | Self-signed, DGA, default template |


**Action:** Block these IPs at your firewall. Monitor for Latrodectus delivery (typically via malicious documents or ISO files).




Priority 2: Kimsuky (North Korea) C2



**IP:** 139.99.86.89

**Score:** 85 (Critical)


North Korean APT infrastructure detected via Pattern 55.3 SSL analysis. Self-signed localhost certificate with expired validity.


**Action:** Block immediately. Review any connections to this IP in the last 30 days.




Priority 3: Red Team Framework C2s



Cobalt Strike (8 servers)


| IP | Score | Notes |

|----|-------|-------|

| 178.239.123.144 | 70 | Self-signed localhost |

| 13.41.96.167 | 45 | AWS - expired cert |

| 170.64.221.190 | 45 | DigitalOcean |

| 170.64.234.187 | 45 | DigitalOcean |

| 111.228.55.96 | 45 | China Telecom |

| 165.245.141.24 | 45 | Korea |

| 8.152.99.85 | 45 | Alibaba Cloud |

| 43.134.61.180 | 30 | Spoofed Baidu cert |


Havoc C2 (2 servers)


| IP | Score | Notes |

|----|-------|-------|

| 157.173.96.123 | 55 | IP-as-CN pattern |

| 64.225.65.17 | 30 | DigitalOcean |


Sliver C2 (3 servers)


| IP | Score | Notes |

|----|-------|-------|

| 213.109.147.96 | 50 | Default cert template |

| 142.11.205.47 | 45 | Spoofed China Mobile cert |

| 193.233.201.12 | 30 | Spoofed Bangladesh military cert |


**Action:** Review network logs for connections to these IPs. Investigate any hits.




Detection Methodology



**Pattern 55.3 - SSL C2 Hunter** uses a 12-signal confidence scoring model:





**Today's Hunt Stats:**

- 845 IOCs swept from ThreatFox

- 297 IP:port targets analyzed

- 65 HTTPS responsive

- 5 Critical, 2 High, 21 Medium confidence




IOCs Added to Index



20 new indicators indexed to DugganUSA threat intel:


Microsoft pulls this feed daily. AT&T pulls this feed daily. Starlink pulls this feed daily. Get the DugganUSA STIX feed — $9/mo →

- 18 C2 server IPs (Latrodectus, Kimsuky, Cobalt Strike, Havoc, Sliver)

- 1 malware family tracker (Latrodectus)

- 1 campaign tracker (Latrodectus February 2026 Surge)


Search at: `https://analytics.dugganusa.com/api/v1/search?q=Latrodectus&indexes=iocs`




Recommended Actions



1. **Immediate:** Block all critical C2 IPs (scores 70+)

2. **24 Hours:** Review firewall logs for any connections to listed IPs

3. **This Week:** Update threat intel feeds with new IOCs

4. **Ongoing:** Monitor for Latrodectus delivery mechanisms (malspam, ISO files)




Latrodectus Background



Latrodectus emerged in late 2023 as an IceID successor. Key characteristics:

- **Delivery:** Malicious documents, ISO files, HTML smuggling

- **Capability:** Loader/downloader for follow-on payloads

- **Operators:** Multiple threat actors use Latrodectus for initial access

- **Payloads:** Typically drops Cobalt Strike, ransomware, or banking trojans


The surge in infrastructure suggests an upcoming campaign.




Attribution Summary



| Actor | Nation | Infrastructure |

|-------|--------|----------------|

| Latrodectus operators | Unknown | 4 critical C2s |

| Kimsuky | North Korea | 1 critical C2 |

| Unknown (Cobalt Strike) | Various | 8 C2 servers |

| Unknown (Havoc) | Various | 2 C2 servers |

| Unknown (Sliver) | Various | 3 C2 servers |




*Published by DugganUSA LLC - Minnesota-based threat intelligence.*


*Pattern 55.3 finds what network logs miss.*




Sources



- ThreatFox (abuse.ch) - IOC feed

- DugganUSA Pattern 55.3 SSL C2 Hunter

- Shannon entropy analysis (MIT, Stanford, Berkeley, U of Toronto)

- JARM TLS fingerprinting (Salesforce)






*Her name was Renee Nicole Good.*


*His name was Alex Jeffery Pretti.*


The cheapest, fastest, most accurate threat feed on the internet.

275+ enterprises pulling daily. 1M+ IOCs. 17.4M indexed documents. We beat Zscaler by 43 days on NrodeCodeRAT. Starter tier $9/mo — less than any competitor’s sales demo.


Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=threat-brief-february-5-2026-latrodectus-c2-infrastructure-surge



 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page