Sekoia identified Exvicy, a Russian-speaking malware-as-a-service ClickFix framework advertised on the Exploit.IN forum and deployed through compromised WordPress sites. The service injects obfuscated JavaScript to display counterfeit Cloudflare Turnstile checks, coercing victims to paste clipboard-delivered PowerShell into the Windows Run dialog. The resulting chain retrieves additional PowerShell payloads and an MSI installer from Cloudflare R2, ultimately installing the legitimate PuTTY SSH client for remote access.
Researchers observed Exvicy command-and-control communications in customer environments and identified about 80 hosts exposing its administration panel by late August. Sekoia assessed with high confidence that Exvicy substantially copies the rival ErrTraffic framework, retaining its obfuscation, deduplication, multilingual capabilities, and much of its C2 logic; unlike ErrTraffic, however, Exvicy uses hardcoded C2 servers rather than Polygon blockchain-based EtherHiding. Organizations should investigate exposure to compromised WordPress sites, fake verification prompts, suspicious PowerShell execution, and the identified Exvicy infrastructure.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Sekoia published research detailing Exvicy's compromised-WordPress ClickFix delivery chain and reporting customer-environment communications with its C2 servers. The researchers assessed with high confidence that Exvicy substantially reused ErrTraffic code, while using hardcoded C2 servers rather than ErrTraffic's Polygon EtherHiding mechanism.
By late August, Sekoia had identified approximately 80 hosts serving Exvicy administration panels, indicating expanded supporting infrastructure.
The Exvicy operator increased the framework's monthly rental price from $1,200 to $2,000, citing the need for frequent updates as detections became more common.
Sekoia identified 13 additional Exvicy panels after pivoting from infrastructure details visible in the operator's advertisement screenshot.
A Russian-speaking actor using the Exvicy handle advertised a ClickFix panel rental service on Exploit.IN for $1,200 per month. The service was designed to distribute malware through compromised WordPress websites.
The ErrTraffic ClickFix framework began being sold on the Exploit.IN cybercrime forum.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.