Late-July campaigns used the ErrTraffic malware-as-a-service platform and ClickFix social engineering to lure victims from compromised WordPress sites into running malicious PowerShell copied to their clipboard. The infection chain fetched fake verification pages, resolved command-and-control through Polygon smart contracts, and used DLL side-loading before hollowing the Remus information stealer into the legitimate Microsoft-signed binary ServiceModelReg.exe.
The Cruciferra loader provided the campaign’s defense-evasion capability by abusing the signed but vulnerable DCRCVDrv.sys driver in a bring-your-own-vulnerable-driver attack to terminate antivirus and EDR processes at kernel level. Researchers said Cruciferra is marketed separately as a MaaS offering, with higher-tier options for UAC bypass and EDR killing, while ErrTraffic is sold as a delivery service with customizable lures and campaign management, showing how operators can combine modular criminal services to distribute infostealers and disable endpoint protections.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers disclosed that the late-July 2026 ErrTraffic ClickFix campaign delivered both the Cruciferra loader and the Remus information stealer. They also revealed that Cruciferra used the signed vulnerable DCRCVDrv.sys driver in a bring-your-own-vulnerable-driver technique to kill 145 antivirus and EDR-related processes.
In late July 2026, eSentire identified several ErrTraffic-generated ClickFix campaigns that attempted to deliver the Cruciferra malware loader via compromised WordPress sites. The infection chain used fake verification lures to trick victims into running malicious PowerShell.
Cruciferra first appeared in November 2025 as a malware-as-a-service offering marketed on underground forums as a loader or crypter with endpoint security-killing capabilities.
LOLDrivers documented that DCRCVDrv.sys exposes IOCTL 0x2205C0, which accepts a PID and invokes ZwTerminateProcess. It also identified Cruciferra's use of C:\Windows\Temp\DCRCVDrv.sys, a driver service, the \\.\DCRCVDRV_U device path, and hashes for the abused driver sample.
Cruciferra was reportedly observed abusing the signed Alinubx.sys driver to terminate antivirus and EDR processes through its arbitrary-process-termination IOCTL functionality. The driver invokes ZwTerminateProcess and can be used in BYOVD attacks against Windows endpoints.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 48 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
8 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecyberveille.ch
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourceinfosecurity-magazine.com
Open sourceesentire.com
Open sourceloldrivers.io
Open sourceloldrivers.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.