A new cybercrime tool called ErrTraffic has emerged, enabling attackers to automate ClickFix attacks by injecting fake browser glitches into compromised websites. This tool leverages a single line of JavaScript code to display convincing visual errors, such as broken text and corrupted fonts, which are tailored to the victim's device and language. The psychological manipulation prompts users to take corrective action, such as downloading malicious payloads or running harmful commands, under the guise of fixing browser or system issues.
ErrTraffic is being sold on underground forums for approximately $800, making it accessible to less skilled cybercriminals and facilitating attacks across multiple platforms, including Windows, Android, macOS, and Linux. The tool's professional design and automation features allow for large-scale deployment, raising concerns about increased supply chain and social engineering risks for organizations using platforms like WordPress, Joomla, and cPanel. Security researchers have highlighted the need for heightened vigilance and defensive strategies to counter this evolving threat.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Follow-on research described a broader self-sustaining cycle in which infostealer malware steals administrative credentials that attackers then use to hijack legitimate business websites for malware hosting and further ClickFix delivery. Hudson Rock and the ClickFix Hunter platform reported tracking more than 1,600 domains involved in these campaigns, showing how compromised legitimate infrastructure helps the activity persist and scale.
Security researchers, including Hudson Rock, documented ErrTraffic as a professionally designed cybercrime tool that injects JavaScript into compromised websites to display fake error messages and trick users into running malicious commands. Their analysis highlighted high reported conversion rates, selective targeting, and use of stolen CMS credentials to spread to additional WordPress, Joomla, and cPanel-managed sites.
A threat actor using the name LenAl began selling ErrTraffic, a self-hosted traffic distribution system that automates ClickFix attacks, for about $800 on Russian-language forums. The tool supports tailored lures and payload delivery across Windows, macOS, Linux, and Android while avoiding users in Russia and nearby CIS countries.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcerescana.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.