logo

ErrTraffic Malware Spreads ClickFix Lures via Hacked WordPress Sites

ID: f51c6ce1-3338-50c7-80da-ca94a157ed34

STIX ID: report--f51c6ce1-3338-50c7-80da-ca94a157ed34

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Do Son

...
...

Sekoia documents ErrTraffic, a ClickFix distribution framework sold as MaaS (advertised by actor “LenAI”) that injects malicious JavaScript into compromised WordPress and fake AI sites to trick visitors into executing PowerShell. The toolkit uses an EtherHiding Polygon smart contract for blockchain-based C2 rotation, serves geo/OS-filtered payloads (Vidar, Stealc, Remus, Salat, SmokeLoader, DanaBot, HijackLoader), employs MU-plugin backdoors and credential-stuffing access, and is offered as a rental/source model with active exploitation observed across many sites; defenders should enable PowerShell ScriptBlock logging, monitor blockchain RPC-to-PowerShell patterns, audit mu-plugins, and enforce MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.