MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
ID: 3da3344d-bb66-5899-988f-937a2412abb2
STIX ID: report--3da3344d-bb66-5899-988f-937a2412abb2
Feed Name: Infosecurity Magazine (News)
eSentire observed a late-July-2026 campaign in which compromised WordPress sites hosted obfuscated ErrTraffic JavaScript that resolved C2 via the Ethereum blockchain and delivered ClickFix social-engineering lures; victims were tricked into running PowerShell commands that sideloaded the Cruciferra loader, which abuses a signed vulnerable driver (DCRCVDrv.sys) to kill AV/EDR processes and uses process hollowing to load the Remus information stealer, illustrating how separate MaaS offerings can be combined to outsource delivery, social engineering and EDR evasion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
