Skip to content
Dark Web Intelligence on X: " NEW CLICKFIX MaaS “EXVICY” ACTIVE ACROSS ...

Dark Web Intelligence on X: " NEW CLICKFIX MaaS “EXVICY” ACTIVE ACROSS ...

X • September 21, 2026

Dark Web Intelligence on X: "🚨 NEW CLICKFIX MaaS “EXVICY” ACTIVE ACROSS COMPROMISED WORDPRESS SITES

Sekoia TDR has uncovered Exvicy, an emerging ClickFix malware-distribution framework being sold on and already observed in active threat infrastructure.

• Exvicy has been advertised as Malware-as-a-Service since May 2026

• The operator initially charged $1,200/month and later increased the price to $2,000/month

• Sekoia assesses with high confidence that Exvicy is a copycat of the rival ErrTraffic framework, built using reused client-side code

• The lures impersonate Cloudflare Turnstile verification challenges

• Victims are instructed to use Win+R and execute attacker-supplied commands — a variation on the now-common ClickFix social-engineering chain

• Researchers identified Exvicy administration panels, PowerShell delivery infrastructure and malicious lure domains

• Sekoia telemetry confirms the framework has been adopted by threat actors and deployed across numerous compromised WordPress sites

• The infrastructure can be used to deliver follow-on malware while bypassing the need for a conventional browser exploit

ClickFix is increasingly becoming a commercialized malware-delivery ecosystem rather than a single technique.

The notable development here is competition between MaaS operators: Exvicy appears to have copied ErrTraffic’s code and is now selling a competing service on a major cybercrime forum, lowering the barrier for other actors to launch convincing clipboard/Run-dialog infection campaigns.

#ClickFix #Exvicy #Malware #MaaS #WordPress #ThreatIntel #CyberCrime #DDW #DarkWeb"

🚨 NEW CLICKFIX MaaS “EXVICY” ACTIVE ACROSS COMPROMISED WORDPRESS SITES

Sekoia TDR has uncovered Exvicy, an emerging ClickFix malware-distribution framework being sold on

and already observed in active threat infrastructure.

• Exvicy has been advertised as Malware-as-a-Service since May 2026

• The operator initially charged $1,200/month and later increased the price to $2,000/month

• Sekoia assesses with high confidence that Exvicy is a copycat of the rival ErrTraffic framework, built using reused client-side code

• The lures impersonate Cloudflare Turnstile verification challenges

• Victims are instructed to use Win+R and execute attacker-supplied commands — a variation on the now-common ClickFix social-engineering chain

• Researchers identified Exvicy administration panels, PowerShell delivery infrastructure and malicious lure domains

• Sekoia telemetry confirms the framework has been adopted by threat actors and deployed across numerous compromised WordPress sites

• The infrastructure can be used to deliver follow-on malware while bypassing the need for a conventional browser exploit

ClickFix is increasingly becoming a commercialized malware-delivery ecosystem rather than a single technique.

The notable development here is competition between MaaS operators: Exvicy appears to have copied ErrTraffic’s code and is now selling a competing service on a major cybercrime forum, lowering the barrier for other actors to launch convincing clipboard/Run-dialog infection campaigns.

🚨 NEW CLICKFIX MaaS “EXVICY” ACTIVE ACROSS COMPROMISED WORDPRESS SITES

Sekoia TDR has uncovered Exvicy, an emerging ClickFix malware-distribution framework being sold on

and already observed in active threat infrastructure.

• Exvicy has been advertised as Malware-as-a-Service since May 2026

• The operator initially charged $1,200/month and later increased the price to $2,000/month

• Sekoia assesses with high confidence that Exvicy is a copycat of the rival ErrTraffic framework, built using reused client-side code

• The lures impersonate Cloudflare Turnstile verification challenges

• Victims are instructed to use Win+R and execute attacker-supplied commands — a variation on the now-common ClickFix social-engineering chain

• Researchers identified Exvicy administration panels, PowerShell delivery infrastructure and malicious lure domains

• Sekoia telemetry confirms the framework has been adopted by threat actors and deployed across numerous compromised WordPress sites

• The infrastructure can be used to deliver follow-on malware while bypassing the need for a conventional browser exploit

ClickFix is increasingly becoming a commercialized malware-delivery ecosystem rather than a single technique.

The notable development here is competition between MaaS operators: Exvicy appears to have copied ErrTraffic’s code and is now selling a competing service on a major cybercrime forum, lowering the barrier for other actors to launch convincing clipboard/Run-dialog infection campaigns.

Extracted Entities

Attack Types (1)

Malware (1)

MITRE ATT&CK (1)

Platforms (1)