ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
Campaign
Summary
Hide ▲
Show ▼
An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware distribution path and helping attackers evade endpoint defenses. The activity was observed in late July 2026 and involved repeated delivery attempts against site visitors. The operation combines social engineering, blockchain-based C2 rotation, and defense evasion into one delivery chain.
Related Happenings
Cruciferra loader EDR-killing delivery chain
Malware Activity
H score18
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
How related:
The payload abused the signed vulnerable DCRCVDrv.sys driver to terminate security-related processes from the Windows kernel.
About this happening:
The Cruciferra loader is being used in a MaaS delivery chain that sideloads DLLs, injects Remus, and disables AV/EDR on Windows endpoints, widening malware del...
Cruciferra loader EDR-killing delivery chain
Malware ActivityHow related: The payload abused the signed vulnerable DCRCVDrv.sys driver to terminate security-related processes from the Windows kernel.
About this happening: The Cruciferra loader is being used in a MaaS delivery chain that sideloads DLLs, injects Remus, and disables AV/EDR on Windows endpoints, widening malware del...
ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion
Threat Actor Meta
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
How related:
ErrTraffic was advertised for $380 per month and provided operators with customizable ClickFix templates, campaign statistics, filtering and a WordPress plugin generator.
About this happening:
ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...
ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion
Threat Actor MetaHow related: ErrTraffic was advertised for $380 per month and provided operators with customizable ClickFix templates, campaign statistics, filtering and a WordPress plugin generator.
About this happening: ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...
StopAndProtect hacked-WordPress cybercrime campaign
Campaign
H score49
First: 19.08.2026 14:25
Last: 19.08.2026 14:25
Sources 1
About this happening:
The StopAndProtect campaign now abuses nearly 2,000 hacked WordPress sites to deliver malware, steal files, and manage infected hosts, expanding a distributed criminal inf...
StopAndProtect hacked-WordPress cybercrime campaign
CampaignAbout this happening: The StopAndProtect campaign now abuses nearly 2,000 hacked WordPress sites to deliver malware, steal files, and manage infected hosts, expanding a distributed criminal inf...
ClickLock ClickFix macOS targeting campaign
Campaign
H score33
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
ClickLock ClickFix macOS targeting campaign
CampaignAbout this happening: Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...
Contagious Interview UNK_DeadDrop GitHub phishing campaign
Campaign
H score37
First: 15.06.2026 22:32
Last: 15.06.2026 22:32
Sources 1
About this happening:
The Contagious Interview cluster is running the UNK_DeadDrop phishing campaign to lure developers with recruitment and code review themes, reaching nearly 100 or...
Contagious Interview UNK_DeadDrop GitHub phishing campaign
CampaignAbout this happening: The Contagious Interview cluster is running the UNK_DeadDrop phishing campaign to lure developers with recruitment and code review themes, reaching nearly 100 or...
Timeline
-
19.08.2026 18:00 2 articles · 1h ago
ErrTraffic ClickFix campaigns deliver Cruciferra from compromised WordPress sites
Initial DisclosureeSentire’s Threat Response Unit described several ErrTraffic-generated ClickFix campaigns observed in late July 2026 that used compromised WordPress sites with obfuscated ErrTraffic JavaScript, fake Google reCAPTCHA, Cloudflare Turnstile, or BSOD lures, and PowerShell stages to sideload Cruciferra and inject the Remus information stealer. The Cruciferra loader was also marketed as an EDR-killing package that abused the signed vulnerable DCRCVDrv.sys driver to terminate antivirus and endpoint detection and response processes, with 145 process names configured for termination by default.
Show sources
- MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra — www.infosecurity-magazine.com — 19.08.2026 18:00
- MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra — www.infosecurity-magazine.com — 19.08.2026 18:00