Back Infosecurity-Magazine New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
A new ClickFix malware-as-a-service (MaaS) framework called Exvicy has been built on code lifted from a rival service, ErrTraffic.
According to a technical write-up published by Sekoia's Threat Detection & Research team on September 21, telemetry from multiple customer environments showed hosts communicating with Exvicy command-and-control (C2) servers. That confirms threat actors are using it to deliver malware through compromised WordPress sites.
The seller, a Russian-speaking actor using the handle Exvicy, has advertised the MaaS on the Exploit.IN forum since May 26. It launched at $1,200 a month and rose to $2,000 in mid-August, with the operator claiming "detections are becoming daily."
When a forum user questioned the price against ErrTraffic , sold on the same forum since December 2025, the seller said his product relied on the Win+R shortcut rather than ErrTraffic's Win+X.
From a Forum Screenshot to Live Panels
Sekoia found the operator's infrastructure through a screenshot in the advert itself. A redacted domain in the admin panel still showed its length, top-level domain and Cloudflare nameserver pair, which narrowed the to five recently registered domains.
One hosted a login page identical to the panel in the screenshot, and a PowerShell downloader there fetched a file matching one in the operator's own payload list. Pivoting from that panel turned up 13 more on July 9, and by late August Sekoia's list of hosts serving the panel ran to 80.
The framework injects obfuscated JavaScript into compromised WordPress sites , which loads a fake Cloudflare Turnstile check. Victims are told to press Win+R, paste and press Enter, running a PowerShell command already copied to their clipboard, with instructions in 13 languages.
The page reports each step back to the operator, including when the victim clicks the fake checkbox, then polls for three minutes to confirm the command ran.
Near-Identical Code, One Real Difference
Sekoia assessed with high confidence that Exvicy reuses ErrTraffic's code in both the injected script and the lure page. Beyond encoded payloads and randomized variable names the injected scripts are nearly identical, and the lure pages the same clipboard, fingerprinting, anti-analysis and polling functions.
It assessed with medium confidence that both operators use the same tool to generate the injected scripts. The clearest technical difference is not the shortcut: ErrTraffic hides its C2 address on the Polygon blockchain, a technique known as EtherHiding , while Exvicy hardcodes two servers.
Sekoia said Exvicy's developer most likely obtained ErrTraffic's source code, either as a paying customer or through a leak. Scraping the client-side code from infected sites and rebuilding the backend was less plausible since that would take as much effort as writing new code itself.
MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra News 19 August 2026
MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
Compromised WordPress Sites Deliver ClickFix Attacks in Global Infostealer Campaign News 11 March 2026
Compromised WordPress Sites Deliver ClickFix Attacks in Global Infostealer Campaign
State- Hackers Behind Majority of Vulnerability Exploits News 29 August 2025
State- Hackers Behind Majority of Vulnerability Exploits
ClickFix Moves into the Browser to Steal Cryptocurrency News 9 September 2026
ClickFix Moves into the Browser to Steal Cryptocurrency
AiTM Phishing Becomes Top Initial Access Threat to Law Firms News 30 July 2026
AiTM Phishing Becomes Top Initial Access Threat to Law Firms
What’s Hot on Infosecurity Magazine?
New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
Cisco Warns of Active Exploitation of Critical ISE Flaw
AI Agent Carries Out Multi-Stage Data Theft Attack
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Most Firms Unable to Recover Quickly from Ransomware
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready
A CISO's Lessons in Ransomware Response and Recovery After a Real-World LockBit Attack
Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems
AI Agent Carries Out Multi-Stage Data Theft Attack
Most Firms Unable to Recover Quickly from Ransomware
Your Security Awareness Programme Isn't Failing, It's Just Not Relevant
Frontier AI: How Cyber Defenders Can Harness the Defender’s Window
How to Secure AI with Modern App and API Strategies
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
