ErrTraffic and Cruciferra ClickFix BYOVD malware activity
Malware Activity
Summary
Hide ▲
Show ▼
The ErrTraffic framework is now being used to deliver Cruciferra through ClickFix lures, adding a BYOVD escalation path that can terminate security processes. The activity routes victims from compromised WordPress sites through an obfuscated JavaScript loader before fetching the next stage from a Polygon smart contract. Recent uses of the framework have also pushed Remus Stealer, Vidar Stealer, Okobot, LegionLoader, OnionDrop-related payloads, and BabaDedaLoader. The chain broadens the malware's reach and makes the delivery path harder to inspect.
Related Happenings
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
Campaign
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
About this happening:
An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
CampaignAbout this happening: An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware...
ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion
Threat Actor Meta
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
About this happening:
ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...
ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion
Threat Actor MetaAbout this happening: ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...
SectopRAT fake Claude installer delivery
Malware Activity
H score19
First: 23.07.2026 22:48
Last: 23.07.2026 22:48
Sources 1
About this happening:
The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. T...
SectopRAT fake Claude installer delivery
Malware ActivityAbout this happening: The SectopRAT malware is being delivered through a fake Claude desktop installer, exposing at least 29 organizations to credential theft and remote hands-on control. T...
ClickFix multi-loader delivery campaign targeting Windows and macOS users
Campaign
H score34
First: 16.06.2026 20:41
Last: 16.06.2026 20:41
Sources 1
About this happening:
The ClickFix malware-delivery campaign is spreading BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, widening risk for Windows and macOS users across several...
ClickFix multi-loader delivery campaign targeting Windows and macOS users
CampaignAbout this happening: The ClickFix malware-delivery campaign is spreading BabaDeda Loader, Lorem Ipsum Loader, and Potemkin, widening risk for Windows and macOS users across several...
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware Activity
H score41
First: 29.05.2026 01:24
Last: 29.05.2026 01:24
Sources 1
About this happening:
GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
GreyVibe custom malware activity with LegionRelay, PhantomRelay, and FallSpy
Malware ActivityAbout this happening: GREYVIBE is a Russian-speaking malware activity targeting Ukraine and Ukraine-related entities since at least August 2025. The group uses spear-phishing e-mails*...
Timeline
-
20.08.2026 20:23 2 articles · 2h ago
ErrTraffic delivers Cruciferra through ClickFix and BYOVD
Campaign Scope UpdateErrTraffic, a malware-as-a-service framework sold by LenAI, has recently been observed distributing multiple threats through compromised WordPress sites, ClickFix social engineering, and EtherHiding. The observed chain uses an obfuscated JavaScript loader, resolves its C2 through a Polygon smart contract, and then delivers Cruciferra, which abuses the vulnerable DCRCVDrv.sys driver in a BYOVD step to escalate privileges, terminate security processes, and support process-hollowing-based theft activity.
Show sources
- ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More — thehackernews.com — 20.08.2026 20:23
- ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More — thehackernews.com — 20.08.2026 20:23