TikTok Videos Spread Latrodectus Malware
- Latrodectus uses ClickFix to execute malware in memory.
- Avoids disk writes, bypassing browser and security detection.
- Acts as a downloader for ransomware and other payloads.
- Successor to IcedID, first documented in April 2024.
- Operation Endgame disrupted its infrastructure in May 2025.
