ErrTraffic is a malware-as-a-service delivery framework and traffic distribution system used to automate ClickFix attacks. Advertised by the cybercriminal actor LenAI on Russian-speaking underground forums since at least December 2025, it provides campaign administration, customizable social-engineering templates, payload management, geographic and referrer filtering, operating-system detection, and visitor and execution statistics. It supports Windows, macOS, Linux, and Android, with observed campaigns prominently targeting Windows users, including Portuguese-speaking users.
ErrTraffic commonly operates through obfuscated JavaScript injected into compromised WordPress websites. Its lures impersonate Cloudflare verification checks, Google reCAPTCHA, browser problems, or Windows blue-screen errors. Visitors are persuaded to execute malicious commands placed on their clipboard, typically launching PowerShell on Windows to retrieve additional payloads. Campaigns also use attacker-controlled websites impersonating AI products. ErrTraffic uses EtherHiding to resolve its active backend through Polygon smart contracts, allowing operators to rotate infrastructure without replacing scripts on compromised sites. Implementations use Base64 and XOR obfuscation and encrypted backend communications using RC4 or AES-GCM.
Associated WordPress components include persistent PHP backdoors capable of harvesting administrator credentials, executing commands, and collecting visitor telemetry. The Analytics operational cluster additionally uses backdoor functionality for cookie exfiltration and WooCommerce skimming; these features are not universal across ErrTraffic deployments. A separate Beer cluster supports multiple affiliates delivering their own payloads.
ErrTraffic has distributed information stealers, loaders, and remote-access malware, including Vidar, Stealc, Remus, SmokeLoader, Cruciferra, and Node.js backdoors. Endpoint process injection, DLL side-loading, and driver-based security-tool termination in these infection chains are capabilities of downstream payloads rather than intrinsic functions of the ErrTraffic delivery framework.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
ErrTraffic is a malicious JavaScript framework primarily injected into compromised WordPress sites to display the ClickFix lure and subsequently deliver malware to visitors.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
WatchGuard telemetry identified a campaign associated with the use of ErrTraffic, a Malware-as-a-Service (MaaS) framework, to distribute malware through ClickFix ... embedded in compromised WordPress websites.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Subsequent PowerShell stages use a legitimate Microsoft-signed program to side-load Cruciferra as mscoree.dll.
Attackers trick users into running PowerShell... The PowerShell command kicks off several stages.
var decoded = _0xe89dd1(_0xaaa71f, _0xb0c5b4); (new Function(decoded))();
The lure copies a hidden PowerShell command to the clipboard. It then tells the user to open PowerShell and paste it. This social trick is called ClickFix.
ErrTraffic also uses Polygon blockchain smart contracts to locate its current command server. That design lets operators rotate infrastructure without rewriting the code planted across compromised sites.
Logique de communication C2 (dl, check) quasi-identique ... Domaines C2 : cloudflare-check[.]net, recaptcha-check[.]com.
Résout son domaine C2 via un smart contract Polygon (méthode getDomain , RPC eth_call )
An obfuscated JavaScript injection contacts attacker-controlled infrastructure, retrieves the lure, and presents a verification page that looks routine.
138 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
25 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A competing ClickFix MaaS framework whose source code, injected scripts, and lure pages were substantially reused by Exvicy. It uses the Polygon blockchain to host or resolve C2 addresses.
A related ClickFix malware-distribution framework whose code is substantially reused by Exvicy, including Base64/XOR obfuscation, FNV-1a deduplication, copyText/xdReq/xdDec functions, multilingual support, and similar C2 communication logic. The content contrasts ErrTraffic’s EtherHiding use with Exvicy’s hard-coded C2 infrastructure.
A rival ClickFix MaaS framework whose injected JavaScript and lure-page functionality were assessed as nearly identical to Exvicy's. Unlike Exvicy, it conceals its C2 address through the Polygon blockchain using EtherHiding.
A Malware-as-a-Service loader targeting Portuguese-speaking users.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.