Back X Dark Web Intelligence on X: " NEW CLICKFIX MaaS “EXVICY” ACTIVE ACROSS ...
Dark Web Intelligence on X: "🚨 NEW CLICKFIX MaaS “EXVICY” ACTIVE ACROSS COMPROMISED WORDPRESS SITES
Sekoia TDR has uncovered Exvicy, an emerging ClickFix malware-distribution framework being sold on and already observed in active threat infrastructure.
• Exvicy has been advertised as Malware-as-a-Service since May 2026
• The operator initially charged $1,200/month and later increased the price to $2,000/month
• Sekoia assesses with high confidence that Exvicy is a copycat of the rival ErrTraffic framework, built using reused client-side code
• The lures impersonate Cloudflare Turnstile verification challenges
• Victims are instructed to use Win+R and execute attacker-supplied commands — a variation on the now-common ClickFix social-engineering chain
• Researchers identified Exvicy administration panels, PowerShell delivery infrastructure and malicious lure domains
• Sekoia telemetry confirms the framework has been adopted by threat actors and deployed across numerous compromised WordPress sites
• The infrastructure can be used to deliver follow-on malware while bypassing the need for a conventional browser exploit
ClickFix is increasingly becoming a commercialized malware-delivery ecosystem rather than a single technique.
The notable development here is competition between MaaS operators: Exvicy appears to have copied ErrTraffic’s code and is now selling a competing service on a major cybercrime forum, lowering the barrier for other actors to launch convincing clipboard/Run-dialog infection campaigns.
#ClickFix #Exvicy #Malware #MaaS #WordPress #ThreatIntel #CyberCrime #DDW #DarkWeb"
🚨 NEW CLICKFIX MaaS “EXVICY” ACTIVE ACROSS COMPROMISED WORDPRESS SITES
Sekoia TDR has uncovered Exvicy, an emerging ClickFix malware-distribution framework being sold on
and already observed in active threat infrastructure.
• Exvicy has been advertised as Malware-as-a-Service since May 2026
• The operator initially charged $1,200/month and later increased the price to $2,000/month
• Sekoia assesses with high confidence that Exvicy is a copycat of the rival ErrTraffic framework, built using reused client-side code
• The lures impersonate Cloudflare Turnstile verification challenges
• Victims are instructed to use Win+R and execute attacker-supplied commands — a variation on the now-common ClickFix social-engineering chain
• Researchers identified Exvicy administration panels, PowerShell delivery infrastructure and malicious lure domains
• Sekoia telemetry confirms the framework has been adopted by threat actors and deployed across numerous compromised WordPress sites
• The infrastructure can be used to deliver follow-on malware while bypassing the need for a conventional browser exploit
ClickFix is increasingly becoming a commercialized malware-delivery ecosystem rather than a single technique.
The notable development here is competition between MaaS operators: Exvicy appears to have copied ErrTraffic’s code and is now selling a competing service on a major cybercrime forum, lowering the barrier for other actors to launch convincing clipboard/Run-dialog infection campaigns.
🚨 NEW CLICKFIX MaaS “EXVICY” ACTIVE ACROSS COMPROMISED WORDPRESS SITES
Sekoia TDR has uncovered Exvicy, an emerging ClickFix malware-distribution framework being sold on
and already observed in active threat infrastructure.
• Exvicy has been advertised as Malware-as-a-Service since May 2026
• The operator initially charged $1,200/month and later increased the price to $2,000/month
• Sekoia assesses with high confidence that Exvicy is a copycat of the rival ErrTraffic framework, built using reused client-side code
• The lures impersonate Cloudflare Turnstile verification challenges
• Victims are instructed to use Win+R and execute attacker-supplied commands — a variation on the now-common ClickFix social-engineering chain
• Researchers identified Exvicy administration panels, PowerShell delivery infrastructure and malicious lure domains
• Sekoia telemetry confirms the framework has been adopted by threat actors and deployed across numerous compromised WordPress sites
• The infrastructure can be used to deliver follow-on malware while bypassing the need for a conventional browser exploit
ClickFix is increasingly becoming a commercialized malware-delivery ecosystem rather than a single technique.
The notable development here is competition between MaaS operators: Exvicy appears to have copied ErrTraffic’s code and is now selling a competing service on a major cybercrime forum, lowering the barrier for other actors to launch convincing clipboard/Run-dialog infection campaigns.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
