Skip to content

ErrTraffic

ErrTraffic is a malware-as-a-service traffic distribution system and JavaScript-based delivery framework designed to operationalize ClickFix social-engineering campaigns.

Profile source: Mallory opens in a new tab

ErrTraffic

Family profile

ErrTraffic is a malware-as-a-service traffic distribution system and JavaScript-based delivery framework designed to operationalize ClickFix social-engineering campaigns. It is marketed by the threat actor LenAI and is commonly deployed through JavaScript injected into compromised WordPress websites. The framework presents device- and language-tailored fake verification or error interfaces, including CAPTCHA, browser-verification, and system-error themes, to induce visitors to copy and execute attacker-supplied commands, commonly through PowerShell or the Windows Run dialog. ErrTraffic supports delivery of operator-selected payloads, including information stealers, loaders, remote-access malware, and Android banking trojans.

ErrTraffic incorporates geolocation, operating-system, browser, and referrer filtering; visitor telemetry; campaign statistics; and configurable lure templates. Its infrastructure uses EtherHiding, querying Polygon smart contracts through public RPC services to resolve and rotate panel or command-and-control infrastructure without updating the JavaScript deployed on compromised sites. Implementations use JavaScript obfuscation and encrypted backend communications to hinder analysis and infrastructure tracking.

Observed ErrTraffic activity includes malicious WordPress plugins and PHP backdoors that provide persistent access to compromised websites, collect administrator credentials, inject malicious client-side scripts, and in some cases support webshell and payment-skimming functions. Documented campaigns have targeted Windows users and have also provided payload workflows for macOS, Android, and Linux. ErrTraffic has been used as the delivery component in modular MaaS operations, including campaigns attempting to deploy Cruciferra and ultimately the Remus information stealer.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Initial Access
  • Persistence
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 2, 2026
Last activity
Sep 9, 2026
Feed role
C2 / Distribution
Host form
0 IP / 123 hostnames

Leading locations

  • US44
  • DE25
  • NL5
  • CY4
  • FR4
  • BR3
  • SG3
  • ZA3
  • ID2
  • IN2
  • BD1
  • BE1

Leading providers

  • Cloudflare, Inc.15
  • Omegatech LTD12
  • Hostinger International Limited9
  • Cloudflare London, LLC8
  • Oracle Corporation8
  • Strato GmbH6

Infrastructure traits

  • Hosting 105
  • Anycast 34

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
LenAI

Several ErrTraffic-generated ClickFix campaigns push the loader; ErrTraffic handles delivery through JavaScript injected into compromised WordPress sites.

Exploited software

Vulnerabilities linked to ErrTraffic

1 CVEs

MITRE ATT&CK

ErrTraffic in ATT&CK

24 distinct techniques

Reporting

Research mentioning ErrTraffic

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.