logo

ErrTraffic Malware Campaign: ClickFix and EtherHiding

ID: 94a09bd1-ceaf-521c-9291-63f9a3dc77b0

STIX ID: report--94a09bd1-ceaf-521c-9291-63f9a3dc77b0

Feed Name: WatchGuard Secplicity Blog

Threat Score
75/100

Date Published: 2026-08-10

Date Updated: 2026-08-19

Author: Euler Neto

...
...

WatchGuard Threat Lab observed an active ErrTraffic MaaS campaign that compromises WordPress sites and uses ClickFix lures plus Polygon-based EtherHiding to dynamically resolve and conceal C2 infrastructure; the operation distributes multiple malware families (Vidar, Okobot, LegionLoader, OnionDrop variants, BabaDedaLoader) using techniques including DLL side-loading, process injection, LOLBINs, PowerShell download chains, and Tor/gRPC backdoors, and the report provides telemetry, PowerShell patterns, domains, and behavioral indicators for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.