ErrTraffic ClickFix campaign delivering Cruciferra through compromised WordPress sites
Campaign
Summary
Hide ▲
Show ▼
An active ErrTraffic-generated ClickFix campaign is using compromised WordPress sites and clipboard-paste PowerShell lures to deliver Cruciferra, widening the malware distribution path and helping attackers evade endpoint defenses. The activity was observed in late July 2026 and involved repeated delivery attempts against site visitors. The operation combines social engineering, blockchain-based C2 rotation, and defense evasion into one delivery chain.
Related Happenings
SVG voicemail phishing campaign
Campaign
H score42
First: 28.08.2026 16:00
Last: 28.08.2026 16:00
Sources 1
About this happening:
The SVG voicemail phishing campaign is a broad-spray operation that delivered 26,589 messages to 5,527 organizations, increasing the chance of email-defense bypass and...
SVG voicemail phishing campaign
CampaignAbout this happening: The SVG voicemail phishing campaign is a broad-spray operation that delivered 26,589 messages to 5,527 organizations, increasing the chance of email-defense bypass and...
Operation QUICSILVER Myanmar espionage campaign
Campaign
H score32
First: 24.08.2026 14:51
Last: 24.08.2026 14:51
Sources 1
About this happening:
The Operation QUICSILVER espionage campaign is actively targeting Myanmar government and information technology sectors with graduation ceremony invitation lures that...
Operation QUICSILVER Myanmar espionage campaign
CampaignAbout this happening: The Operation QUICSILVER espionage campaign is actively targeting Myanmar government and information technology sectors with graduation ceremony invitation lures that...
ErrTraffic and Cruciferra ClickFix BYOVD malware activity
Malware Activity
H score72
First: 20.08.2026 20:23
Last: 20.08.2026 20:23
Sources 1
About this happening:
The ErrTraffic framework is now being used to deliver Cruciferra through ClickFix lures, adding a BYOVD escalation path that can terminate security processes....
ErrTraffic and Cruciferra ClickFix BYOVD malware activity
Malware ActivityAbout this happening: The ErrTraffic framework is now being used to deliver Cruciferra through ClickFix lures, adding a BYOVD escalation path that can terminate security processes....
Cruciferra loader EDR-killing delivery chain
Malware Activity
H score18
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
How related:
The payload abused the signed vulnerable DCRCVDrv.sys driver to terminate security-related processes from the Windows kernel.
About this happening:
The Cruciferra loader is being used in a MaaS delivery chain that sideloads DLLs, injects Remus, and disables AV/EDR on Windows endpoints, widening malware del...
Cruciferra loader EDR-killing delivery chain
Malware ActivityHow related: The payload abused the signed vulnerable DCRCVDrv.sys driver to terminate security-related processes from the Windows kernel.
About this happening: The Cruciferra loader is being used in a MaaS delivery chain that sideloads DLLs, injects Remus, and disables AV/EDR on Windows endpoints, widening malware del...
ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion
Threat Actor Meta
H score32
First: 19.08.2026 18:00
Last: 19.08.2026 18:00
Sources 1
How related:
ErrTraffic was advertised for $380 per month and provided operators with customizable ClickFix templates, campaign statistics, filtering and a WordPress plugin generator.
About this happening:
ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...
ErrTraffic and Cruciferra subscription MaaS ecosystem outsources delivery and EDR evasion
Threat Actor MetaHow related: ErrTraffic was advertised for $380 per month and provided operators with customizable ClickFix templates, campaign statistics, filtering and a WordPress plugin generator.
About this happening: ErrTraffic and Cruciferra are being sold as subscription MaaS services, expanding the underground market for ClickFix delivery and EDR-killing capabilities. Th...
Timeline
-
19.08.2026 18:00 2 articles · 13d ago
ErrTraffic ClickFix campaigns deliver Cruciferra from compromised WordPress sites
Initial DisclosureeSentire’s Threat Response Unit described several ErrTraffic-generated ClickFix campaigns observed in late July 2026 that used compromised WordPress sites with obfuscated ErrTraffic JavaScript, fake Google reCAPTCHA, Cloudflare Turnstile, or BSOD lures, and PowerShell stages to sideload Cruciferra and inject the Remus information stealer. The Cruciferra loader was also marketed as an EDR-killing package that abused the signed vulnerable DCRCVDrv.sys driver to terminate antivirus and endpoint detection and response processes, with 145 process names configured for termination by default.
Show sources
- MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra — www.infosecurity-magazine.com — 19.08.2026 18:00
- MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra — www.infosecurity-magazine.com — 19.08.2026 18:00