Skip to content
Exvicy Malware Framework Leverages ErrTraffic Codebase

Exvicy Malware Framework Leverages ErrTraffic Codebase

First seen 21 Sep 2026, 15:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 15:29 UTC

Sekoia's TDR team identified Exvicy, a new ClickFix malware distribution framework, which is a copycat of ErrTraffic. Advertised on the Russian-speaking forum Exploit.IN since May 26, 2026, Exvicy is sold as Malware-as-a-Service (MaaS) and has seen active adoption by threat actors. The framework injects obfuscated JavaScript into compromised WordPress sites, utilizing social engineering tactics to trick victims into executing malicious PowerShell commands. The price for Exvicy's subscription increased from $1,200 to $2,000 due to rising detection rates. Technical analysis confirms that Exvicy reuses ErrTraffic's code, including its JavaScript and Command and Control (C2) communication logic. Sekoia's telemetry indicates multiple customer environments are communicating with Exvicy's C2 servers, confirming its operational use in malware delivery.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-05-26
Exvicy advertised on Exploit.IN
The Exvicy ClickFix framework was first advertised at a price of $1,200 per month.
Sekoia
2026-08-15
Subscription price increased
The operator raised the subscription fee for Exvicy to $2,000 per month, citing increased detection rates.
Sekoia
2026-09-21
Sekoia publishes technical write-up
Sekoia's TDR team released findings confirming Exvicy's similarities to ErrTraffic and its active use in malware campaigns.
Infosecurity-Magazine

More articles in this cluster (3)

Following this threat?

Track ClickFix and Polygon in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed