Skip to content

ErrTraffic

ErrTraffic is a malware-as-a-service traffic distribution system and malicious JavaScript framework used to automate ClickFix social-engineering campaigns.

Profile source: Mallory opens in a new tab

ErrTraffic

Family profile

ErrTraffic is a malware-as-a-service traffic distribution system and malicious JavaScript framework used to automate ClickFix social-engineering campaigns. It is injected into compromised websites, particularly WordPress sites, where it selectively presents fake browser errors, CAPTCHA or verification pages, and system-error lures based on visitor attributes such as operating system, language, geography, and referrer. The lures commonly instruct victims to paste and execute a clipboard-populated command, frequently through PowerShell on Windows, to retrieve attacker-selected payloads.

ErrTraffic uses EtherHiding-style dead-drop resolution through Polygon smart contracts to obtain and rotate its active backend infrastructure without modifying JavaScript already implanted on compromised sites. Recent variants use JavaScript obfuscation and encrypted panel communications, provide campaign telemetry and payload-delivery functions, and support lure templates for Windows and macOS. The framework has distributed diverse follow-on malware, including information stealers, loaders, remote-access tools, and banking malware.

ErrTraffic has been advertised on Russian-language cybercrime forums and Telegram by an actor using the name LenAI since late 2025. Research distinguishes an active affiliate-oriented Beer cluster from an Analytics cluster likely operated independently with an earlier ErrTraffic codebase. Some associated WordPress compromises use credential-harvesting backdoors, webshell functionality, and persistent malicious plugins to retain control of websites and expand the delivery infrastructure. ErrTraffic targets or supports Windows, macOS, Android, and Linux payload delivery; the observed ClickFix execution chains most prominently affect Windows users.

Capabilities

  • Credential Theft
  • Initial Access
  • Persistence

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 23, 2026
Last activity
Aug 30, 2026
Feed role
C2 / Distribution
Host form
0 IP / 1731 hostnames

Leading locations

  • US696
  • DE174
  • FR160
  • BR63
  • ES60
  • GB59
  • CH43
  • IT41
  • IN40
  • PL23
  • ZA23
  • BE22

Leading providers

  • Cloudflare, Inc.127
  • Cloudflare London, LLC120
  • Oracle Corporation115
  • OVH SAS98
  • IONOS SE81
  • Hostinger International Limited78

Infrastructure traits

  • Hosting 1648
  • Anycast 369
  • Proxy 9

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
LenAI

Several ErrTraffic-generated ClickFix campaigns push the loader; ErrTraffic handles delivery through JavaScript injected into compromised WordPress sites.

Exploited software

Vulnerabilities linked to ErrTraffic

1 CVEs

MITRE ATT&CK

ErrTraffic in ATT&CK

24 distinct techniques

Reporting

Research mentioning ErrTraffic

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.