ErrTraffic is a malware-as-a-service traffic-distribution and malware-delivery framework used to operate ClickFix campaigns from compromised WordPress websites. Advertised since late 2025 by the actor LenAI on Russian-speaking cybercrime forums, it provides operators with configurable social-engineering templates, traffic filtering, campaign statistics, WordPress compromise tooling, and payload-delivery functionality. It has been associated with the delivery of infostealers, loaders, remote-access tools, and other commodity malware.
ErrTraffic injects obfuscated JavaScript into compromised sites to present counterfeit browser-verification, CAPTCHA, or system-error prompts, including Cloudflare Turnstile, Google reCAPTCHA, and blue-screen themes. The lures manipulate visitors into pasting clipboard-populated commands into Windows Run or PowerShell. The framework can collect visitor and interaction telemetry, identify operating-system and browser characteristics, adapt lure language, and retrieve staged payloads after victim execution.
A defining feature is EtherHiding-based dead-drop resolution: injected scripts query Polygon smart contracts through public RPC services to obtain current command-and-control or panel infrastructure. This permits infrastructure rotation without reinjecting every compromised site. ErrTraffic uses encoding, XOR-based obfuscation, and encrypted panel communications to hinder inspection. Versions have supported Windows, macOS, Linux, and Android-oriented delivery workflows.
ErrTraffic activity has been divided into Analytics and Beer clusters. The Beer cluster has been assessed as the active LenAI-operated rental service used by multiple affiliates, while the Analytics cluster appears consistent with a separate operator using an older acquired version. In addition to JavaScript injection, observed WordPress compromises have involved persistent must-use-plugin backdoors that capture administrator credentials, collect visitor data, provide webshell access, and in some cases enable payment-card skimming. ErrTraffic has also been used as the delivery component in campaigns that deployed Cruciferra, after which downstream stages installed the Remus information stealer and impaired endpoint defenses.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ErrTraffic is a malicious JavaScript framework primarily injected into compromised WordPress sites to display the ClickFix lure and subsequently deliver malware to visitors.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Several ErrTraffic-generated ClickFix campaigns push the loader; ErrTraffic handles delivery through JavaScript injected into compromised WordPress sites.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Subsequent PowerShell stages use a legitimate Microsoft-signed program to side-load Cruciferra as mscoree.dll.
Attackers trick users into running PowerShell... The PowerShell command kicks off several stages.
var decoded = _0xe89dd1(_0xaaa71f, _0xb0c5b4); (new Function(decoded))();
The lure copies a hidden PowerShell command to the clipboard. It then tells the user to open PowerShell and paste it. This social trick is called ClickFix.
ErrTraffic also uses Polygon blockchain smart contracts to locate its current command server. That design lets operators rotate infrastructure without rewriting the code planted across compromised sites.
Logique de communication C2 (dl, check) quasi-identique ... Domaines C2 : cloudflare-check[.]net, recaptcha-check[.]com.
Résout son domaine C2 via un smart contract Polygon (méthode getDomain , RPC eth_call )
An obfuscated JavaScript injection contacts attacker-controlled infrastructure, retrieves the lure, and presents a verification page that looks routine.
138 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A competing ClickFix MaaS framework whose source code, injected scripts, and lure pages were substantially reused by Exvicy. It uses the Polygon blockchain to host or resolve C2 addresses.
A related ClickFix malware-distribution framework whose code is substantially reused by Exvicy, including Base64/XOR obfuscation, FNV-1a deduplication, copyText/xdReq/xdDec functions, multilingual support, and similar C2 communication logic. The content contrasts ErrTraffic’s EtherHiding use with Exvicy’s hard-coded C2 infrastructure.
A rival ClickFix MaaS framework whose injected JavaScript and lure-page functionality were assessed as nearly identical to Exvicy's. Unlike Exvicy, it conceals its C2 address through the Polygon blockchain using EtherHiding.
A Malware-as-a-Service loader targeting Portuguese-speaking users.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.