Last seven days
- First activity
- Aug 23, 2026
- Last activity
- Aug 30, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 1731 hostnames
ErrTraffic is a malware-as-a-service traffic distribution system and malicious JavaScript framework used to automate ClickFix social-engineering campaigns.
Profile source: Mallory opens in a new tabErrTraffic
ErrTraffic is a malware-as-a-service traffic distribution system and malicious JavaScript framework used to automate ClickFix social-engineering campaigns. It is injected into compromised websites, particularly WordPress sites, where it selectively presents fake browser errors, CAPTCHA or verification pages, and system-error lures based on visitor attributes such as operating system, language, geography, and referrer. The lures commonly instruct victims to paste and execute a clipboard-populated command, frequently through PowerShell on Windows, to retrieve attacker-selected payloads.
ErrTraffic uses EtherHiding-style dead-drop resolution through Polygon smart contracts to obtain and rotate its active backend infrastructure without modifying JavaScript already implanted on compromised sites. Recent variants use JavaScript obfuscation and encrypted panel communications, provide campaign telemetry and payload-delivery functions, and support lure templates for Windows and macOS. The framework has distributed diverse follow-on malware, including information stealers, loaders, remote-access tools, and banking malware.
ErrTraffic has been advertised on Russian-language cybercrime forums and Telegram by an actor using the name LenAI since late 2025. Research distinguishes an active affiliate-oriented Beer cluster from an Analytics cluster likely operated independently with an earlier ErrTraffic codebase. Some associated WordPress compromises use credential-harvesting backdoors, webshell functionality, and persistent malicious plugins to retain control of websites and expand the delivery infrastructure. ErrTraffic targets or supports Windows, macOS, Android, and Linux payload delivery; the observed ClickFix execution chains most prominently affect Windows users.
C2 tracking
Derp observations, rolling seven-day window
Samples
0dfed8e2a27f0a2806b67813b8b5c0898a7e6ec310fb58bd54862da4017d3b7a 1c419ceb3f6db2fc8de74f8f6668a4609064fd8ba6badbfbe9663d45ad2f9c8c 1e2f3669b83e9f6b5beaa7653d8b11aa764aa708f2c1eb4fe7588b5a5d178e96 1ea627ffe4a73e75e83554e5d48d4dc2e736ee512b094391b19557740952ffa4 1f03b1dbb4d21d2726a2bd98c5da932e628ab8e3c4304297d94a7b5f4c3a5e23 20b4b7dcf3c84279a21d1f5bf871cfaa57cf9e2f821093485413d811d41a3ae5 702929da3c1caa872456081c5faf0174929da41d2007008989ebb49cb9c29030 73d45bf1d7c13984aa6c8c22943c19bbb798f4547c9535ccfd0730dadc9c4cf4 8bc5eaa1b4db5b8dfbe0e8574d05f0ceffd6308e606f385e591e3002f6cec5a2 c0469aa4f32b26fa235f126556718a5798787aa187b1cddcf35a42b6cd74068b Reported operators
Several ErrTraffic-generated ClickFix campaigns push the loader; ErrTraffic handles delivery through JavaScript injected into compromised WordPress sites.
Exploited software
MITRE ATT&CK
Reporting
Late-July campaigns used the ErrTraffic malware-as-a-service platform and ClickFix social engineering to lure victims from compromised WordPress sites into running malicious PowerShell copied to their clipboard. The infection chain fetched fake verification pages, resolved command-and-control through Polygon smart contracts, and used DLL side-loading before hollowing the Remus information stealer into the legitimate Microsoft-signed binary ServiceModelReg.exe. The Cruciferra loader provided the campaign’s defense-evasion capability by abusing the signed but vulnerable DCRCVDrv.sys driver in a bring-your-own-vulnerable-driver attack to terminate antivirus and EDR processes at kernel level. Researchers said Cruciferra is marketed separately as a MaaS offering, with higher-tier options for UAC bypass and EDR killing, while ErrTraffic is sold as a delivery service with customizable lures and campaign management, showing how operators can combine modular criminal services to distribute infostealers and disable endpoint protections.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.