Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework
ID: ab9d6fb9-055d-5365-9c6d-47a3da8e751a
STIX ID: report--ab9d6fb9-055d-5365-9c6d-47a3da8e751a
Feed Name: Sekoia.com
ErrTraffic is a modular malicious JavaScript Traffic Distribution System sold as a Malware-as-a-Service that injects ClickFix social‑engineering lures into compromised WordPress sites and attacker-controlled landing pages (including sites impersonating AI platforms). The Sekoia TDR analysis identifies two operational clusters (“Analytics” and “Beer”) that use blockchain-based EtherHiding for dead-drop resolution, distribute multiple malware families (notably Vidar, DanaBot, HijackLoader), leverage diverse PHP backdoors and webshells for persistence, and are offered to affiliates via subscription/source-code sales on cybercrime forums; the report includes forensic timelines, IoCs, and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
