ErrTraffic is a malware distribution framework and traffic distribution system used to automate ClickFix social-engineering attacks. It is commonly deployed on compromised websites, especially WordPress sites, where injected JavaScript presents fake verification, CAPTCHA, browser error, update, or system-failure prompts that trick visitors into manually executing malicious commands. The framework has been marketed in underground forums as a self-hosted crimeware offering associated with the actor LenAI and has been described as operating under a malware-as-a-service model.
ErrTraffic is notable for combining website compromise, selective victim filtering, and decentralized staging. Observed campaigns used compromised WordPress administrator access and malicious must-use plugins or PHP backdoors to maintain persistence on websites, harvest administrator credentials, inject obfuscated JavaScript, and collect visitor telemetry. The framework supports geofiltering, operating-system detection, multilingual lures, and tailored payload delivery. It has also used EtherHiding techniques by querying Polygon smart contracts through public RPC infrastructure to retrieve or rotate command-and-control configuration, complicating infrastructure disruption and enabling rapid changes without reinfecting every compromised site.
The framework itself is primarily a delivery platform rather than a single payload family. Campaigns attributed to ErrTraffic have distributed a range of malware, especially Windows infostealers and loaders such as Vidar, Stealc, Remus, Salat, SmokeLoader, HijackLoader, DanaBot, and other loader- or RAT-linked payloads; some reporting also describes delivery of macOS, Android, and Linux payloads. On infected endpoints, downstream malware has been observed stealing browser data, saved credentials, cookies, and cryptocurrency-wallet information, while some payload chains included defense evasion, process injection, DLL sideloading, and backdoor functionality. Fake AI-themed websites and compromised WordPress properties have both been used as delivery surfaces.
ErrTraffic has been linked to multiple operational clusters with differing infrastructure and delivery logic, including clusters referred to as Analytics and Beer. Reporting assesses the Beer cluster as the active rental offering and the Analytics cluster as likely operated by a separate actor using purchased source code. The ecosystem around ErrTraffic illustrates the industrialization of ClickFix operations by lowering the barrier to entry for affiliates and enabling scalable malware delivery through social engineering rather than software exploitation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ErrTraffic is a malicious JavaScript framework primarily injected into compromised WordPress sites to display the ClickFix lure and subsequently deliver malware to visitors.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ErrTraffic is a malicious JavaScript framework primarily injected into compromised WordPress sites to display the ClickFix lure and subsequently deliver malware to visitors.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
ThreatFox lists the exact domain as a high-confidence botnet_cc indicator tagged c2 and ErrTraffic.
The script communicates with the server API by specifying an action type in the “a” parameter... cfg : Fetches the latest configuration. dl : Fetches the latest payload.
110 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ErrTraffic is a malware delivery and traffic distribution operation that uses compromised WordPress sites, ClickFix-style social engineering, and Polygon blockchain smart-contract lookups to dynamically resolve attacker infrastructure and deliver follow-on payloads.
ErrTraffic is referenced as the malware family/tag associated with the suspicious domain enter-press-cdn.info, which is identified as a high-confidence botnet command-and-control indicator tied to an unknown loader.
A malware distribution framework operated as MaaS that uses ClickFix lures on compromised WordPress sites, includes a TDS component, and hides C2 infrastructure via EtherHiding in the blockchain to deliver malware at scale.
A malicious JavaScript framework and TDS sold as a MaaS offering. It is injected into compromised WordPress sites or attacker-controlled lure sites, uses ClickFix social engineering and EtherHiding/Polygon smart contracts to resolve C2 infrastructure, and delivers follow-on payloads to victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.