Skip to content

Campaign record

Latrodectus and Supper in Poland

One intrusion at a large Polish organisation, from a fake verification page to Latrodectus v2.3 and the Supper backdoor, as reconstructed by CERT Polska.

Status as last assessed
Active
First seen
Unrecorded
Last seen
Unrecorded
Indicators
15
Sources
1
Targets
Windows
  • Fake CAPTCHA verification
  • Latrodectus
  • Supper
  • Compromised WordPress site

Original research

This page summarises and structures that research; it is not a substitute for the original.

Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.

Summary

CERT Polska assisted law enforcement after an intrusion at a large Polish organisation, and traced the way in to one user who obeyed a bogus human-verification page. The instruction was to paste a line into the Windows Run box; it fetched content with curl and piped it into PowerShell. The payload was a DLL side-loaded by a legitimate Intel executable in an %APPDATA% folder, unpacking to Latrodectus version 2.3 and tagged internally with the group name Kallichore; the analysts found no public account of the 2.x branch. Two further DLLs taken off the same workstation unpacked to Supper, a backdoor CERT Polska associates with the run-up to ransomware, persisting as a scheduled task named to resemble a Google updater. The report does not establish which stage put the Supper files on the machine, only that the intrusion began at the verification page.

Execution mechanisms

How the pasted command actually ran, as the published accounts describe it. Every row under “Mechanism” is one this campaign records; “Across the corpus” is the share of the 44 published campaigns in this corpus that record the same one — a baseline we can only state because we hold the whole set.

Execution mechanisms recorded for this campaign, with their frequency across the corpus
MechanismAcross the corpusATT&CK
Windows Run dialog23 of 4452%T1204.004
PowerShell19 of 4443%T1059.001

Both of these mechanisms appear together in 12 of the 44 campaigns on record, this one included. We record a mechanism only where a source describes one: an absent mechanism means nobody wrote it down, not that it did not happen.

Indicators

15 indicators, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator. No observation date is recorded for any of them.

Indicators recorded for this campaign, shown defanged
IndicatorTypeRoleAssessmentReport an error
domain, shown defanged for safety: jzluw dot comdomainPayload hostNot yet assessedReport an error in domain record 31569892-8899-4aca-8adf-2e59c86c1514
domain, shown defanged for safety: naintn dot comdomainPayload hostNot yet assessedReport an error in domain record 1c941cdb-d9d3-4b5f-b39f-7fb96ebe8f40
domain, shown defanged for safety: fadoklismokley dot comdomainCommand and controlAttacker-controlledReport an error in domain record 726fe754-f8e4-448a-b1f6-2212403486e5
domain, shown defanged for safety: gasrobariokley dot comdomainCommand and controlAttacker-controlledReport an error in domain record 8542a70a-6ca3-459f-8101-1c8437395cd3
ip, shown defanged for safety: 146 dot 19 dot 49 dot 130ipCommand and controlNot yet assessedReport an error in ip record 48f4f317-3865-435d-a3ed-631105ccc11d
ip, shown defanged for safety: 162 dot 19 dot 199 dot 110ipCommand and controlNot yet assessedReport an error in ip record 5df33e2c-6362-4dc7-bbda-709aca4737e7
ip, shown defanged for safety: 171 dot 130 dot 169 dot 141ipCommand and controlNot yet assessedReport an error in ip record 5bdbfb0e-5266-41f5-9985-825c89134ed0
ip, shown defanged for safety: 185 dot 233 dot 166 dot 27ipCommand and controlNot yet assessedReport an error in ip record 53f8e7fc-50ba-4e29-9111-11752df1ca13
ip, shown defanged for safety: 85 dot 239 dot 54 dot 130ipCommand and controlNot yet assessedReport an error in ip record cd9d007c-bf3f-4e56-b109-2e19758d8614
url, shown defanged for safety: hxxps colon slash slash fadoklismokley dot com/work/urlCommand and controlAttacker-controlledReport an error in url record 76c9fe8e-f543-47fd-8701-8159f26f64d3
url, shown defanged for safety: hxxps colon slash slash gasrobariokley dot com/work/urlCommand and controlAttacker-controlledReport an error in url record 141527b0-296f-4bdc-bbe4-5de90ac1b80f
sha256, shown defanged for safety: 21b953dc06933a69bcb2e0ea2839b47288fc8f577e183c95a13fc3905061b4e6sha256SampleNot yet assessedReport an error in sha256 record a8f12776-2601-4745-99a4-1fb03adb1405
sha256, shown defanged for safety: 2528df60e55f210a6396dd7740d76afe30d5e9e8684a5b8a02a63bdcb5041bfcsha256SampleNot yet assessedReport an error in sha256 record e74d2a08-7fd7-4dfc-9a6d-7f0bed0e919d
sha256, shown defanged for safety: 6673794376681c48ce4981b42e9293eee010d60ef6b100a3866c0abd571ea648sha256SampleNot yet assessedReport an error in sha256 record f6b2ee46-b96c-413d-a93a-1b329c08a5fd
sha256, shown defanged for safety: be5bcdfc0dbe204001b071e8270bd6856ce6841c43338d8db914e045147b0e77sha256SampleNot yet assessedReport an error in sha256 record 4657973c-9436-4bed-8fc6-030845f9cde0

“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.

Not on this record

This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.

Cite as

ClickFixReport, “Latrodectus and Supper in Poland”, campaign ID 7bdefaad, retrieved 2026-08-07, snapshot fb0eed7.

https://clickfixreport.com/campaigns/7bdefaad/latrodectus-clickfix

Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.