Find notable cyber news and cases, enriched with sources, timelines, and signals.

Exvicy and ErrTraffic code reuse analysis

Technical Analysis
First reported
Last updated
Happening score
H score 22
1 unique sources, 1 articles

Summary

Hide ▲

Exvicy now has a high-confidence code link to ErrTraffic, giving defenders a clearer basis for attribution and detection across the shared delivery chain. The comparison shows the two frameworks reuse the same logic in the injected script and lure page, not just similar messaging. Shared functions include clipboard handling, fingerprinting, anti-analysis, and polling routines, while Exvicy differs by hardcoding two C2 servers. The code overlap exposes a reusable technical fingerprint for tracking related ClickFix infrastructure.

Related Happenings

LummaStealer infection surge via CastleLoader

Malware Activity
H score30 First: 11.02.2026 19:02 Last: 11.02.2026 19:02 Sources 1

About this happening: The LummaStealer infostealer operation now includes a widespread ClickFix campaign observed in February 2026 that abuses Windows Terminal (wt.exe) instead of the R...

Latest development: 06.03.2026 08:44

Microsoft disclosed a widespread ClickFix social-engineering campaign that uses Windows Terminal (wt.exe) instead of the Windows Run dialog to trick users into launching malicious commands, then chains through Terminal, PowerShell, cmd.exe, and MSBuild.exe to download payloads, set persistence via scheduled tasks, configure Microsoft Defender exclusions, and inject Lumma Stealer into chrome.exe and msedge.exe with QueueUserAPC().

APT36 / SideCopy phishing-led campaign targeting Indian defense organizations

Campaign
H score38 First: 11.02.2026 16:52 Last: 11.02.2026 16:52 Sources 1

About this happening: A phishing-led APT36 / SideCopy campaign is targeting Indian defense and government-aligned organizations, using cross-platform RATs to steal sensitive data and ke...

ErrTraffic-LenAI ecosystem shift changes threat-actor operations

Threat Actor Meta
H score28 First: 30.12.2025 23:08 Last: 30.12.2025 23:08 Sources 1

How related: A new ClickFix malware-as-a-service (MaaS) framework called Exvicy has been built on code lifted from a rival service, ErrTraffic.

About this happening: ErrTraffic is a self-hosted TDS and ClickFix delivery service that turns compromised websites into lure pages that prompt selected visitors to run malicious instru...

Latest development: 21.09.2026 17:30

Sekoia's Threat Detection & Research team identified Exvicy, a ClickFix malware-as-a-service framework, through telemetry from multiple customer environments and found hosts communicating with its C2 servers. The framework reuses ErrTraffic code in both the injected script and the lure page, and Exvicy hardcodes two servers instead of hiding the C2 address with EtherHiding on the Polygon blockchain.

Timeline

  1. 21.09.2026 17:30 2 articles · 6h ago

    Exvicy reuses ErrTraffic code in its ClickFix delivery chain

    Technical Analysis Update

    Telemetry from multiple customer environments showed hosts communicating with Exvicy command-and-control servers, and Sekoia's Threat Detection & Research team reported that Exvicy, a ClickFix malware-as-a-service framework used to deliver malware through compromised WordPress sites, reuses ErrTraffic code in both the injected script and the lure page. The comparison found nearly identical clipboard, fingerprinting, anti-analysis, and polling logic, while Exvicy hardcodes two C2 servers instead of using ErrTraffic's Polygon-based EtherHiding.

    Show sources