Campaign record
Latrodectus from Storm-0249
Latrodectus delivered by Storm-0249 from broken-into websites
- Status as last assessed
- Active
- First seen
- 2025-05-14
- Last seen
- 2025-05-14
- Indicators
- 1
- Sources
- 1
- Targets
- Windows
- Fake browser verification challenge
- Latrodectus
- Compromised WordPress site
Original research
- Microsoft Threat Intelligence2025-08-21Vendor researchFirst account
Think before you Click(Fix): Analyzing the ClickFix social engineering technique
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Storm-0249, a group Microsoft associates with Latrodectus and other first-stage malware, changed its way in at the start of March 2025. Where it had sent PDFs or links by mail, sometimes themed around copyright complaints, it began taking over legitimate websites — possibly through weaknesses in WordPress — and grafting a lure onto them. A visitor sees the genuine page for a moment before it is swapped for a demand to prove they are human, dressed up as a Cloudflare Turnstile check so the interruption reads as routine. Doing as instructed means pasting a command into the Windows Run dialog. The owners of the hosting sites are victims here, not participants; Microsoft names none of them. The host reached by the pasted command is recorded as cqsf[.]live, seen on 14 May 2025.
Execution mechanisms
The only execution mechanism any published account describes for this campaign is Windows Run dialog (T1204.004), which 23 of the 44 published campaigns in this corpus also record (52%).
Indicators
1 indicator, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.
| Indicator | Type | Role | Assessment | First seen | Last seen | Report an error |
|---|---|---|---|---|---|---|
| domain, shown defanged for safety: cqsf dot live | domain | Payload host | Not yet assessed | 2025-05-14 | 2025-05-14 | Report an error in domain record 9e970f5a-3676-4758-abe6-a1981598cc52 |
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “Latrodectus from Storm-0249”, campaign ID 0216315e, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/0216315e/latrodectus-clickfix-drive-by
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.