Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomwar

August 20, 2026

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

August 20, 2026

How Borussia Dortmund’s IT Chief Makes the Case for Cybersecurity

August 20, 2026
Facebook X (Twitter) Instagram
Thursday, August 20
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra
News

MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra

Team-CWDBy Team-CWDAugust 19, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A malware-as-a-service (MaaS) campaign has combined ClickFix social engineering with the ErrTraffic delivery service and Cruciferra loader, giving attackers a way to distribute malware while disabling endpoint security processes.

In a new advisory published earlier today, eSentire’s Threat Response Unit (TRU) described several ErrTraffic-generated ClickFix campaigns observed in late July 2026 that attempted to deliver Cruciferra.

The loader is marketed on underground forums with features designed to kill antivirus and endpoint detection and response (EDR) processes.

Turning Compromised Sites Into ClickFix Delivery Platforms

The campaign began with compromised WordPress sites containing an obfuscated ErrTraffic JavaScript injection.

The script used the Ethereum blockchain to resolve a command-and-control (C2) address before retrieving JavaScript for a fake Google reCAPTCHA, Cloudflare Turnstile or Blue Screen of Death (BSOD) lure.

The lure copied a malicious PowerShell command to the victim’s clipboard and instructed them to paste and run it.

Additional PowerShell stages then used a legitimate Microsoft-signed binary to sideload the Cruciferra DLL, which used process hollowing to inject the Remus information stealer into a second Microsoft-signed binary, ServiceModelReg.exe.

Compromised WordPress sites have previously been used to deliver ClickFix malware, but the eSentire campaign combined the technique with two separate MaaS offerings.

ErrTraffic was advertised for $380 per month and provided operators with customizable ClickFix templates, campaign statistics, filtering and a WordPress plugin generator. Its use of blockchain-based infrastructure also allowed operators to rotate C2 domains without changing the JavaScript injected into compromised websites.

Cruciferra’s EDR-killing package cost $1,200 per month and is marketed as a loader capable of disabling security products.

The payload abused the signed vulnerable DCRCVDrv.sys driver to terminate security-related processes from the Windows kernel. eSentire found 145 process names configured for termination by default, most of them antivirus and EDR products.

The driver is not currently known to Microsoft or LOLDrivers, meaning it will not be caught by the vulnerable driver blocklist. eSentire recommended blocking it directly by hash.

Read more on EDR-killing techniques: Ransomware Groups Increasingly Deploy EDR Kill Technique

The campaign showed how operators could combine separate MaaS products to outsource delivery, social engineering and defense evasion rather than developing each capability themselves.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMalicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Next Article Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
Team-CWD
  • Website

Related Posts

News

Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomwar

August 20, 2026
News

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

August 20, 2026
News

OpenAI Tightens AI Safeguards Following Hugging Face Incident

August 19, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

All Major LLMs Exposed to Multi-Turn Manipulation, Warn Researchers

May 27, 20269 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How cybercriminals are targeting content creators

November 26, 2025

What parents should know to protect their children from doxxing

November 28, 2025

Your information is on the dark web. What happens next?

January 13, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.