Skip to content
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code

New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code

Infosecurity-Magazine September 21, 2026

A new ClickFix malware-as-a-service (MaaS) framework called Exvicy has been built on code lifted from a rival service, ErrTraffic.

According to a technical write-up published by Sekoia's Threat Detection & Research team on September 21, telemetry from multiple customer environments showed hosts communicating with Exvicy command-and-control (C2) servers. That confirms threat actors are using it to deliver malware through compromised WordPress sites.

The seller, a Russian-speaking actor using the handle Exvicy, has advertised the MaaS on the Exploit.IN forum since May 26. It launched at $1,200 a month and rose to $2,000 in mid-August, with the operator claiming "detections are becoming daily."

When a forum user questioned the price against ErrTraffic , sold on the same forum since December 2025, the seller said his product relied on the Win+R shortcut rather than ErrTraffic's Win+X.

From a Forum Screenshot to Live Panels

Sekoia found the operator's infrastructure through a screenshot in the advert itself. A redacted domain in the admin panel still showed its length, top-level domain and Cloudflare nameserver pair, which narrowed the to five recently registered domains.

One hosted a login page identical to the panel in the screenshot, and a PowerShell downloader there fetched a file matching one in the operator's own payload list. Pivoting from that panel turned up 13 more on July 9, and by late August Sekoia's list of hosts serving the panel ran to 80.

The framework injects obfuscated JavaScript into compromised WordPress sites , which loads a fake Cloudflare Turnstile check. Victims are told to press Win+R, paste and press Enter, running a PowerShell command already copied to their clipboard, with instructions in 13 languages.

The page reports each step back to the operator, including when the victim clicks the fake checkbox, then polls for three minutes to confirm the command ran.

Near-Identical Code, One Real Difference

Sekoia assessed with high confidence that Exvicy reuses ErrTraffic's code in both the injected script and the lure page. Beyond encoded payloads and randomized variable names the injected scripts are nearly identical, and the lure pages the same clipboard, fingerprinting, anti-analysis and polling functions.

It assessed with medium confidence that both operators use the same tool to generate the injected scripts. The clearest technical difference is not the shortcut: ErrTraffic hides its C2 address on the Polygon blockchain, a technique known as EtherHiding , while Exvicy hardcodes two servers.

Sekoia said Exvicy's developer most likely obtained ErrTraffic's source code, either as a paying customer or through a leak. Scraping the client-side code from infected sites and rebuilding the backend was less plausible since that would take as much effort as writing new code itself.

MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra News 19 August 2026

MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra

Compromised WordPress Sites Deliver ClickFix Attacks in Global Infostealer Campaign News 11 March 2026

Compromised WordPress Sites Deliver ClickFix Attacks in Global Infostealer Campaign

State- Hackers Behind Majority of Vulnerability Exploits News 29 August 2025

State- Hackers Behind Majority of Vulnerability Exploits

ClickFix Moves into the Browser to Steal Cryptocurrency News 9 September 2026

ClickFix Moves into the Browser to Steal Cryptocurrency

AiTM Phishing Becomes Top Initial Access Threat to Law Firms News 30 July 2026

AiTM Phishing Becomes Top Initial Access Threat to Law Firms

What’s Hot on Infosecurity Magazine?

New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

Cisco Warns of Active Exploitation of Critical ISE Flaw

AI Agent Carries Out Multi-Stage Data Theft Attack

PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug

Most Firms Unable to Recover Quickly from Ransomware

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready

A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack

Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems

AI Agent Carries Out Multi-Stage Data Theft Attack

Most Firms Unable to Recover Quickly from Ransomware

Your Security Awareness Programme Isn't Failing, It's Just Not Relevant

Frontier AI: How Cyber Defenders Can Harness the Defender’s Window

How to Secure AI with Modern App and API Strategies

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust