ErrTraffic is a cybercrime traffic distribution and malware delivery framework used to automate ClickFix social-engineering attacks. It is commonly deployed by injecting malicious JavaScript into compromised websites, especially WordPress sites, where it presents fake browser or system error lures such as CAPTCHA prompts, browser glitches, update prompts, missing-font messages, or crash-themed warnings to trick visitors into manually executing attacker-supplied commands. The framework has been marketed in Russian-speaking criminal forums since late 2025 and is associated with the actor using the alias LenAI. It has been offered both as a hosted or rental-style crimeware service and as source code or self-hosted tooling.
Operationally, ErrTraffic functions as a traffic distribution system that fingerprints visitors by operating system, browser, language, and geography, then selectively serves tailored lures and payload chains. Observed campaigns have targeted Windows, macOS, Android, and Linux users. On Windows, ErrTraffic has been used to deliver infostealers and loaders including Vidar, Stealc, DanaBot delivery chains, HijackLoader, SmokeLoader, and other RAT or loader payloads. macOS and Android delivery support has also been advertised and observed in reporting. The framework supports multilingual lure content, geofiltering, and selective exclusions for CIS countries, reflecting deliberate victim shaping and evasion.
A notable feature of ErrTraffic is its use of EtherHiding-style blockchain-based dead-drop resolution. Rather than hardcoding infrastructure, injected scripts query Polygon smart contracts through public RPC endpoints to retrieve current command-and-control or staging information. This design complicates infrastructure disruption and enables rapid rotation of backend resources. Researchers have also documented encrypted backend communications, obfuscated JavaScript, inline script generation, and clipboard-delivered PowerShell execution flows as part of its delivery chain.
ErrTraffic has been repeatedly linked to compromises of WordPress sites. In observed intrusions, attackers used stolen administrator credentials to access sites, deploy PHP backdoors in must-use plugin locations, inject malicious JavaScript into page templates or footers, capture additional credentials, and maintain persistence. Some backdoor variants also supported command execution, anti-detection logic, analytics collection, and in certain cases skimming functionality. This makes ErrTraffic more than a simple lure kit: it is part of a broader website-compromise and malware-distribution ecosystem that supports persistence on compromised web infrastructure while funneling victims into downstream payload delivery.
Multiple operational clusters have been identified, including distinct groups using different smart-contract patterns, JavaScript implementations, and payload sets. One cluster has been assessed as a MaaS offering rented to affiliates, while another appears more consistent with a single operator using purchased source code. Campaigns have included both compromised legitimate websites and attacker-controlled fake AI-themed sites impersonating well-known brands or services to increase lure effectiveness.
ErrTraffic is best characterized as a malware delivery framework or loader ecosystem rather than a single endpoint payload family. Its primary significance lies in industrializing ClickFix attacks, scaling malware distribution through compromised websites, and combining social engineering, web compromise, credential theft, persistence, and resilient blockchain-backed staging.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ErrTraffic is a malicious JavaScript framework primarily injected into compromised WordPress sites to display the ClickFix lure and subsequently deliver malware to visitors.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ErrTraffic is a malicious JavaScript framework primarily injected into compromised WordPress sites to display the ClickFix lure and subsequently deliver malware to visitors.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
ThreatFox lists the exact domain as a high-confidence botnet_cc indicator tagged c2 and ErrTraffic.
The script communicates with the server API by specifying an action type in the “a” parameter... cfg : Fetches the latest configuration. dl : Fetches the latest payload.
83 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ErrTraffic is referenced as the malware family/tag associated with the suspicious domain enter-press-cdn.info, which is identified as a high-confidence botnet command-and-control indicator tied to an unknown loader.
A malware distribution framework operated as MaaS that uses ClickFix lures on compromised WordPress sites, includes a TDS component, and hides C2 infrastructure via EtherHiding in the blockchain to deliver malware at scale.
A malicious JavaScript framework and TDS sold as a MaaS offering. It is injected into compromised WordPress sites or attacker-controlled lure sites, uses ClickFix social engineering and EtherHiding/Polygon smart contracts to resolve C2 infrastructure, and delivers follow-on payloads to victims.
A multi-platform traffic distribution system built for ClickFix campaigns. It compromises WordPress sites with a PHP backdoor, injects obfuscated JavaScript, uses blockchain-based EtherHiding to retrieve attacker-controlled infrastructure, filters and redirects visitors to ClickFix lures, and delivers OS-specific payloads for Windows or macOS.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.