Last seven days
- First activity
- Sep 2, 2026
- Last activity
- Sep 9, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 123 hostnames
ErrTraffic is a malware-as-a-service traffic distribution system and JavaScript-based delivery framework designed to operationalize ClickFix social-engineering campaigns.
Profile source: Mallory opens in a new tabErrTraffic
ErrTraffic is a malware-as-a-service traffic distribution system and JavaScript-based delivery framework designed to operationalize ClickFix social-engineering campaigns. It is marketed by the threat actor LenAI and is commonly deployed through JavaScript injected into compromised WordPress websites. The framework presents device- and language-tailored fake verification or error interfaces, including CAPTCHA, browser-verification, and system-error themes, to induce visitors to copy and execute attacker-supplied commands, commonly through PowerShell or the Windows Run dialog. ErrTraffic supports delivery of operator-selected payloads, including information stealers, loaders, remote-access malware, and Android banking trojans.
ErrTraffic incorporates geolocation, operating-system, browser, and referrer filtering; visitor telemetry; campaign statistics; and configurable lure templates. Its infrastructure uses EtherHiding, querying Polygon smart contracts through public RPC services to resolve and rotate panel or command-and-control infrastructure without updating the JavaScript deployed on compromised sites. Implementations use JavaScript obfuscation and encrypted backend communications to hinder analysis and infrastructure tracking.
Observed ErrTraffic activity includes malicious WordPress plugins and PHP backdoors that provide persistent access to compromised websites, collect administrator credentials, inject malicious client-side scripts, and in some cases support webshell and payment-skimming functions. Documented campaigns have targeted Windows users and have also provided payload workflows for macOS, Android, and Linux. ErrTraffic has been used as the delivery component in modular MaaS operations, including campaigns attempting to deploy Cruciferra and ultimately the Remus information stealer.
C2 tracking
Derp observations, rolling seven-day window
Samples
05f06e445e2a315d1a6e5eb07679c3c868953ea6d5e04141553be37b73709e26 59542af0729d86a74643ebd93085df1f44fe722a64ce46f2ad6c50dc02d03f58 dc7aec96b3959a8467556bb4fe013e006cb6be84ba66d72fa4b8d52fdd9038ff ec321669aa549c30fd18a0e82c65bd555b678f7c8edd969ecf99288d1f0aff17 f43a8bded8118fe101f6563149783be06097cb02d56a07af03bf6b7c84169898 0dbeafe4c5fc35b1ede5f0587e9f4c67edc2a77bb11b424fe1791d11971844bc 19c8ce2b9514b28fd597e6530af776819c19eb6d32bc4493b4b57cd6262d90eb a2f68148eb75ea9a6230673f53a848e25400ad2aaa8b29d50c57348f942e43b4 14118afcba7e47cdfd4a0fa328a9ab07010708c9688e6806371c13cfe27ccfc7 522cbd6b2cc512875655e0483ed370b7744a1a8c9614f7035bfdabf747bb969c Reported operators
Several ErrTraffic-generated ClickFix campaigns push the loader; ErrTraffic handles delivery through JavaScript injected into compromised WordPress sites.
Exploited software
MITRE ATT&CK
Reporting
Late-July campaigns used the ErrTraffic malware-as-a-service platform and ClickFix social engineering to lure victims from compromised WordPress sites into running malicious PowerShell copied to their clipboard. The infection chain fetched fake verification pages, resolved command-and-control through Polygon smart contracts, and used DLL side-loading before hollowing the Remus information stealer into the legitimate Microsoft-signed binary ServiceModelReg.exe. The Cruciferra loader provided the campaign’s defense-evasion capability by abusing the signed but vulnerable DCRCVDrv.sys driver in a bring-your-own-vulnerable-driver attack to terminate antivirus and EDR processes at kernel level. Researchers said Cruciferra is marketed separately as a MaaS offering, with higher-tier options for UAC bypass and EDR killing, while ErrTraffic is sold as a delivery service with customizable lures and campaign management, showing how operators can combine modular criminal services to distribute infostealers and disable endpoint protections.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.