tope, also known as cybershell_master, is an English-speaking cybercriminal assessed with high confidence to be a customer of the ErrTraffic malware-as-a-service ecosystem rather than its core developer or operator. The actor is linked to use of the subscription-based ErrTraffic framework, a traffic-distribution and malware-delivery platform deployed on compromised WordPress sites to present ClickFix social-engineering lures and deliver follow-on malware. Available evidence indicates that tope leverages advanced webshell tradecraft to deploy ErrTraffic across numerous compromised WordPress environments. The actor is associated with operations consistent with the ErrTraffic “Beer” cluster, which has been assessed as the active rental offering used by multiple affiliates. In that ecosystem, affiliates use dedicated blockchain-resolved infrastructure and compromised websites to inject obfuscated JavaScript, profile visitors, retrieve lure content, and trigger PowerShell-based payload execution. Malware families delivered through this cluster have included infostealers, loaders, remote-access tooling, and related commodity malware. The broader intrusion pattern tied to ErrTraffic includes use of stolen administrator credentials for WordPress access, installation of PHP backdoors and webshells, JavaScript injection, anti-analysis and anti-detection measures, and post-compromise persistence on web servers. tope has been specifically associated with advanced webshell usage and is assessed as a likely affiliate or customer operating within the ErrTraffic service model. The actor’s activity aligns with financially motivated malware distribution and credential-driven compromise of internet-facing content-management systems, especially WordPress sites, to monetize traffic through malware delivery.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.