Cruciferra loader EDR-killing delivery chain
Malware Activity
Summary
Hide ▲
Show ▼
The Cruciferra loader is being used in a MaaS delivery chain that sideloads DLLs, injects Remus, and disables AV/EDR on Windows endpoints, widening malware delivery while reducing detection.
Related Happenings
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
Campaign
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
How related:
In a new advisory published earlier today, eSentire’s Threat Response Unit (TRU) described several ErrTraffic-generated ClickFix campaigns observed in late July 2026 that attempted to deliver Cruciferra.
About this happening:
An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
CampaignHow related: In a new advisory published earlier today, eSentire’s Threat Response Unit (TRU) described several ErrTraffic-generated ClickFix campaigns observed in late July 2026 that attempted to deliver Cruciferra.
About this happening: An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion
Threat Actor Meta
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
How related:
ErrTraffic was advertised for $380 per month and provided operators with customizable ClickFix templates, campaign statistics, filtering and a WordPress plugin generator.
About this happening:
ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...
ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion
Threat Actor MetaHow related: ErrTraffic was advertised for $380 per month and provided operators with customizable ClickFix templates, campaign statistics, filtering and a WordPress plugin generator.
About this happening: ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...
Potemkin loader delivering EtherRAT and RMMProject in memory
Malware Activity
H score29
First: 16.06.2026 20:41
Last: 16.06.2026 20:41
Sources 1
About this happening:
The Potemkin loader is delivering EtherRAT and RMMProject to Windows systems, giving operators in-memory payload execution and browser credential theft. The lo...
Potemkin loader delivering EtherRAT and RMMProject in memory
Malware ActivityAbout this happening: The Potemkin loader is delivering EtherRAT and RMMProject to Windows systems, giving operators in-memory payload execution and browser credential theft. The lo...
LummaStealer infection surge via CastleLoader
Malware Activity
H score30
First: 11.02.2026 19:02
Last: 11.02.2026 19:02
Sources 1
About this happening:
The LummaStealer infostealer operation now includes a widespread ClickFix campaign observed in February 2026 that abuses Windows Terminal (wt.exe) instead of the R...
LummaStealer infection surge via CastleLoader
Malware ActivityAbout this happening: The LummaStealer infostealer operation now includes a widespread ClickFix campaign observed in February 2026 that abuses Windows Terminal (wt.exe) instead of the R...
Latest development: 06.03.2026 08:44
Microsoft disclosed a widespread ClickFix social-engineering campaign that uses Windows Terminal (wt.exe) instead of the Windows Run dialog to trick users into launching malicious commands, then chains through Terminal, PowerShell, cmd.exe, and MSBuild.exe to download payloads, set persistence via scheduled tasks, configure Microsoft Defender exclusions, and inject Lumma Stealer into chrome.exe and msedge.exe with QueueUserAPC().
Tax-themed phishing campaign targeting Indian users with persistent access payloads
Campaign
H score32
First: 26.01.2026 19:01
Last: 26.01.2026 19:01
Sources 1
About this happening:
An ongoing tax-themed phishing campaign is targeting Indian users with a multi-stage backdoor, creating persistent access for continuous monitoring and data exfi...
Tax-themed phishing campaign targeting Indian users with persistent access payloads
CampaignAbout this happening: An ongoing tax-themed phishing campaign is targeting Indian users with a multi-stage backdoor, creating persistent access for continuous monitoring and data exfi...
Timeline
-
19.08.2026 18:00 2 articles · 1h ago
eSentire details a Cruciferra delivery chain using ClickFix and ErrTraffic
Initial DisclosureeSentire’s Threat Response Unit described ErrTraffic-generated ClickFix campaigns observed in late July 2026 that began on compromised WordPress sites, used an Ethereum blockchain-resolved command-and-control address, delivered fake Google reCAPTCHA, Cloudflare Turnstile, or Blue Screen of Death lures, and chained PowerShell stages to sideload a Cruciferra DLL that injected the Remus information stealer into ServiceModelReg.exe. The same campaign also abused the signed vulnerable DCRCVDrv.sys driver to terminate security-related processes from the Windows kernel, with 145 process names configured for termination by default, mostly antivirus and endpoint detection and response products.
Show sources
- MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra — www.infosecurity-magazine.com — 19.08.2026 18:00
- MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra — www.infosecurity-magazine.com — 19.08.2026 18:00