Researchers detailed ErrTraffic, a growing malware-as-a-service framework that injects JavaScript into compromised WordPress sites to present ClickFix lures and deliver malware. The operation uses EtherHiding on the Polygon blockchain to conceal and rotate command-and-control infrastructure, and investigators identified two clusters—Analytics and Beer—with different smart-contract usage, C2 methods, JavaScript implementations, and payload delivery patterns. The Beer cluster is assessed as the active rental service used by multiple affiliates, while Analytics appears tied to a single operator using acquired source code.
Campaigns linked to ErrTraffic used stolen WordPress administrator credentials, PHP backdoors, malicious MU-plugins, and fake AI-themed sites impersonating Google Antigravity and ChatGPT to distribute malware including Vidar, Stealc, DanaBot, HijackLoader, Remus, Salat, and SmokeLoader. Separate reporting also exposed a live malware distribution backend after a researcher found an unsecured PHP installer at /install/install.php, allowing administrative access to the panel that managed hosted payloads, dynamic download pages, and multi-stage redirection chains; although the operators patched that weakness, the infrastructure reportedly remains active. Defenders were provided with domains, delivery URLs, and file hashes to support detection and response.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-17, Gurucul published a threat research notice summarizing the ErrTraffic framework and its use of compromised WordPress sites, ClickFix lures, and EtherHiding. The notice added domains, a malware delivery URL, and file hashes as indicators of compromise while citing the underlying Sekoia research.
On 2026-06-16, Sekoia published research on ErrTraffic, a Malware-as-a-Service JavaScript framework injected into compromised WordPress sites to deliver ClickFix lures and malware. The report described its use of EtherHiding on the Polygon blockchain, identified the distinct Analytics and Beer clusters, and linked campaigns delivering malware including Vidar, DanaBot, HijackLoader, Stealc, Remus, Salat, and SmokeLoader.
The operators later fixed the exposed installation page weakness that had allowed administrative takeover of the malware platform. Despite the patch, the malicious infrastructure reportedly remained active and continued distributing malware.
After the dashboard initially returned a 500 Internal Server Error, the threat actor repaired the backend configuration. The researcher was able to regain access because the platform did not invalidate an existing server-side session token.
A security researcher found a live malware distribution platform with an exposed "/install/install.php" endpoint that could be rerun in production, allowing initialization against a controlled MySQL instance and creation of a new administrator account. The access exposed a functioning backend used for malware delivery, including a PHP admin panel, database, hosted payloads, and redirection chains.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 83 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourceblog.sekoia.io
Open sourcecybersecuritynews.com
Open sourceguard.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.