Find notable cyber news and cases, enriched with sources, timelines, and signals.

ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware distribution path and helping attackers evade endpoint defenses. The activity was observed in late July 2026 and involved repeated delivery attempts against site visitors. The operation combines social engineering, blockchain-based C2 rotation, and defense evasion into one delivery chain.

Related Happenings

Cruciferra loader EDR-killing delivery chain

Malware Activity
H score18 First: 19.08.2026 18:00 Last: 19.08.2026 18:00 Sources 1

How related: The payload abused the signed vulnerable DCRCVDrv.sys driver to terminate security-related processes from the Windows kernel.

About this happening: The Cruciferra loader is being used in a MaaS delivery chain that sideloads DLLs, injects Remus, and disables AV/EDR on Windows endpoints, widening malware del...

ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion

Threat Actor Meta
H score32 First: 19.08.2026 18:00 Last: 19.08.2026 18:00 Sources 1

How related: ErrTraffic was advertised for $380 per month and provided operators with customizable ClickFix templates, campaign statistics, filtering and a WordPress plugin generator.

About this happening: ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...

StopAndProtect hacked-WordPress cybercrime campaign

Campaign
H score49 First: 19.08.2026 14:25 Last: 19.08.2026 14:25 Sources 1

About this happening: The StopAndProtect campaign now abuses nearly 2,000 hacked WordPress sites to deliver malware, steal files, and manage infected hosts, expanding a distributed criminal inf...

ClickLock ClickFix macOS targeting campaign

Campaign
H score33 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...

Contagious Interview UNK_DeadDrop GitHub phishing campaign

Campaign
H score37 First: 15.06.2026 22:32 Last: 15.06.2026 22:32 Sources 1

About this happening: The Contagious Interview cluster is running the UNK_DeadDrop phishing campaign to lure developers with recruitment and code review themes, reaching nearly 100 or...

Timeline

  1. 19.08.2026 18:00 2 articles · 1h ago

    ErrTraffic ClickFix campaigns deliver Cruciferra from compromised WordPress sites

    Initial Disclosure

    eSentire’s Threat Response Unit described several ErrTraffic-generated ClickFix campaigns observed in late July 2026 that used compromised WordPress sites with obfuscated ErrTraffic JavaScript, fake Google reCAPTCHA, Cloudflare Turnstile, or BSOD lures, and PowerShell stages to sideload Cruciferra and inject the Remus information stealer. The Cruciferra loader was also marketed as an EDR-killing package that abused the signed vulnerable DCRCVDrv.sys driver to terminate antivirus and endpoint detection and response processes, with 145 process names configured for termination by default.

    Show sources