Campaign record
Latrodectus and Supper in Poland
One intrusion at a large Polish organisation, from a fake verification page to Latrodectus v2.3 and the Supper backdoor, as reconstructed by CERT Polska.
- Status as last assessed
- Active
- First seen
- Unrecorded
- Last seen
- Unrecorded
- Indicators
- 15
- Sources
- 1
- Targets
- Windows
- Fake CAPTCHA verification
- Latrodectus
- Supper
- Compromised WordPress site
Original research
- CERT Polska2026-02-17CERT / national bodyFirst account
ClickFix in action: how fake captcha can lead to a company-wide infection
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
CERT Polska assisted law enforcement after an intrusion at a large Polish organisation, and traced the way in to one user who obeyed a bogus human-verification page. The instruction was to paste a line into the Windows Run box; it fetched content with curl and piped it into PowerShell. The payload was a DLL side-loaded by a legitimate Intel executable in an %APPDATA% folder, unpacking to Latrodectus version 2.3 and tagged internally with the group name Kallichore; the analysts found no public account of the 2.x branch. Two further DLLs taken off the same workstation unpacked to Supper, a backdoor CERT Polska associates with the run-up to ransomware, persisting as a scheduled task named to resemble a Google updater. The report does not establish which stage put the Supper files on the machine, only that the intrusion began at the verification page.
Execution mechanisms
How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.
| Mechanism | Across the corpus | ATT&CK |
|---|---|---|
| Windows Run dialog | 23 of 4452% | T1204.004 |
| PowerShell | 19 of 4443% | T1059.001 |
Both of these mechanisms appear together in 12 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.
Indicators
15 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “Latrodectus and Supper in Poland”, campaign ID 7bdefaad, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/7bdefaad/latrodectus-clickfix
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.