A fake CAPTCHA social-engineering lure was used to gain initial access in an intrusion later tied to the Interlock ransomware group. Investigators found that a user was tricked into pasting and running a malicious PowerShell command through the Windows Run dialog, launching a staged infection chain that downloaded and executed a payload from rebrand[.]ly/openCaptcha into the victim's %TEMP% directory as KjGryNSu.exe.
Analysis of the PowerShell stage showed the script suppressed normal output, fetched the executable, and ran it, leading to deployment of Supper, a heavily obfuscated DLL backdoor that provided command execution, DLL loading, credential theft, and lateral movement capability. Beazley Security also observed the attackers installing CrossTec and using a Dormouse installer, while law-enforcement data from a seized server linked the activity log for the intrusion to Interlock, indicating the operation was likely intended to end in ransomware deployment.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Law enforcement later informed the targeted organization that an activity log recovered from a seized server tied the intrusion to the emerging Interlock ransomware group. This clarified that the likely end goal of the operation was ransomware deployment.
Beazley Security's MXDR and MDR teams identified, responded to, and contained the intrusion in a client environment late last year before broader compromise occurred. At that stage, Beazley had not yet confirmed the attackers' final objective.
Beazley's earlier observations showed the threat actor attempting commands to extract the SAM hive, and the Supper implant was assessed as the primary tool for credential theft and lateral activity. This reflected progression beyond initial access toward broader compromise.
Beazley identified the second-stage payload as Supper, a heavily obfuscated DLL-based implant with anti-analysis features. The malware provided command-line access, could execute commands through cmd.exe, and could run supplied DLLs via rundll functionality.
After initial access, the attackers downloaded multiple files and installed CrossTec remote administration software on the compromised machine. Beazley also observed use of a Dormouse installer, which was the notable component used to fetch the next-stage payload.
In the Beazley intrusion, the malicious PowerShell downloaded active.exe and saved it locally as asdin2oe.exe before execution. The separate analysis similarly shows the PowerShell stage downloading an executable into %TEMP% and launching it, confirming staged payload delivery behavior.
Beazley determined that a client intrusion began when a user followed a fake CAPTCHA prompt and pasted a malicious PowerShell command into the Windows Run dialog. A separate malware-analysis reference describes the same lure pattern, where encoded PowerShell downloads and executes a payload from rebrand[.]ly/openCaptcha.
Beazley reported that VirusTotal searches on a hardcoded Supper filename returned 13 related samples first seen from September through December, indicating a broader campaign using similarly named executables and callback infrastructure. Submission data suggested targeting in India, Canada, Germany, the Netherlands, France, and the United States.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.