Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign
ID: 344521be-bd3f-5c49-898e-73dae41475c5
STIX ID: report--344521be-bd3f-5c49-898e-73dae41475c5
Feed Name: LevelBlue SpiderLabs Blog
ErrTraffic V3 is a commercially offered Traffic Distribution System used in ClickFix campaigns that compromises WordPress sites by installing a mu‑plugin PHP backdoor to capture administrator credentials and persist; it injects obfuscated JavaScript that retrieves attacker URLs and payloads from blockchain smart contracts (EtherHiding), serves multilingual ClickFix lures (Cloudflare, reCAPTCHA, fake BSOD, etc.), and delivers OS‑specific malware. The report includes technical analysis of the multi‑stage chain, backend API and encryption modes, infrastructure and ASN clustering, IOCs, and notes critical OpSec failures (hardcoded keys) that enable defenders to track and decrypt the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
