ErrTraffic is a cybercriminal malware delivery service associated with ClickFix-style social-engineering campaigns and broader web-inject activity. It has been described as operating under a ClickFix-as-a-Service model, providing affiliates or customers with ready-made infrastructure to deliver malware of their choice. Activity linked to ErrTraffic has included fake CAPTCHA prompts tailored to a victim’s operating system and designed to trick users into manually executing commands, particularly through terminal or PowerShell-based workflows. In observed campaigns, Windows users were targeted with delivery of NetSupport RAT, while separate macOS payloads were also prepared. ErrTraffic is part of the wider criminal ecosystem that adopted malicious web injects beyond the earlier TA569/FakeUpdates pattern. It has been identified alongside clusters such as ClearFake and ZPHP as one of the groups using compromised websites and deceptive browser content to drive malware installation. Available reporting supports ErrTraffic as an enablement or distribution service rather than a state-sponsored espionage actor. Its known behavior centers on social-engineering-based initial access and malware deployment, with infrastructure intended to support downstream payload delivery by affiliates.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Likely operated the ClickFix campaign against Gizmodo readers, providing ClickFix-as-a-Service infrastructure to distribute malware via fake CAPTCHA prompts.
A ClickFix-as-a-service operation whose affiliates deliver malware via fake CAPTCHA-style prompts that trick users into executing malicious commands.
Threat cluster identified as using web inject campaigns beyond the TA569 ecosystem.
Threat cluster involved in web-inject campaigns using compromised websites and fake update style delivery.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.