ErrTraffic Malware Campaign: ClickFix and EtherHiding
ID: 94a09bd1-ceaf-521c-9291-63f9a3dc77b0
STIX ID: report--94a09bd1-ceaf-521c-9291-63f9a3dc77b0
Feed Name: WatchGuard Secplicity Blog
WatchGuard Threat Lab observed an active ErrTraffic MaaS campaign that compromises WordPress sites and uses ClickFix lures plus Polygon-based EtherHiding to dynamically resolve and conceal C2 infrastructure; the operation distributes multiple malware families (Vidar, Okobot, LegionLoader, OnionDrop variants, BabaDedaLoader) using techniques including DLL side-loading, process injection, LOLBINs, PowerShell download chains, and Tor/gRPC backdoors, and the report provides telemetry, PowerShell patterns, domains, and behavioral indicators for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
