Find notable cyber news and cases, enriched with sources, timelines, and signals.

ErrTraffic and Cruciferra ClickFix BYOVD malware activity

Malware Activity
First reported
Last updated
Happening score
H score 72
1 unique sources, 1 articles

Summary

Hide ▲

The ErrTraffic framework is now being used to deliver Cruciferra through ClickFix lures, adding a BYOVD escalation path that can terminate security processes. The activity routes victims from compromised WordPress sites through an obfuscated JavaScript loader before fetching the next stage from a Polygon smart contract. Recent uses of the framework have also pushed Remus Stealer, Vidar Stealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader. The chain broadens the malware's reach and makes the delivery path harder to inspect.

Related Happenings

ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites

Campaign
H score32 First: 19.08.2026 18:00 Last: 19.08.2026 18:00 Sources 1

About this happening: An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...

ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion

Threat Actor Meta
H score32 First: 19.08.2026 18:00 Last: 19.08.2026 18:00 Sources 1

About this happening: ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...

SectopRAT fake Claude installer delivery

Malware Activity
H score19 First: 23.07.2026 22:48 Last: 23.07.2026 22:48 Sources 1

About this happening: The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. T...

ClickFix multi-loader delivery campaign targeting Windows and macOS users

Campaign
H score34 First: 16.06.2026 20:41 Last: 16.06.2026 20:41 Sources 1

About this happening: The ClickFix malware-delivery campaign is spreading BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, widening risk for Windows and macOS users across several...

GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy

Malware Activity
H score41 First: 29.05.2026 01:24 Last: 29.05.2026 01:24 Sources 1

About this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...

Timeline

  1. 20.08.2026 20:23 2 articles · 2h ago

    ErrTraffic delivers Cruciferra through ClickFix and BYOVD

    Campaign Scope Update

    ErrTraffic, a malware-as-a-service framework sold by LenAI, has recently been observed distributing multiple threats through compromised WordPress sites, ClickFix social engineering, and EtherHiding. The observed chain uses an obfuscated JavaScript loader, resolves its C2 through a Polygon smart contract, and then delivers Cruciferra, which abuses the vulnerable DCRCVDrv.sys driver in a BYOVD step to escalate privileges, terminate security processes, and support process-hollowing-based theft activity.

    Show sources