CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

ErrTraffic

campaign · campaign:sekoia-errtraffic-clickfix-maas-polygon-c2

ErrTraffic, ClickFix MaaS distribution framework with EtherHiding/Polygon C2 resolution; EU WordPress targeting

Coverage
1
first 2026-06-17 → last 2026-06-17
Latest activity
2026-06-17
Sekoia: ErrTraffic, a ClickFix Malware-as-a-Service framework resolving C2 through the Polygon blockchain
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, education, media · regions: europe, apac
Sources cited
2
2 hosts

Story timeline

  1. 2026-06-17Sekoia: ErrTraffic, a ClickFix Malware-as-a-Service framework resolving C2 through the Polygon blockchain
    research

Entries about ErrTraffic (1)

2026-06-17 · view entry permalink →

NOTABLE

Sekoia: ErrTraffic, a ClickFix Malware-as-a-Service framework resolving C2 through the Polygon blockchain

ClickFix (fake browser/update dialogues that trick users into pasting attacker PowerShell) is maturing into a productised delivery channel, as this and the next item show. Sekoia's TDR team analysed ErrTraffic, a ClickFix distribution framework sold as MaaS by an actor using the handle "LenAI" on the Exploit.IN forum since at least December 2025 (Sekoia TDR, 2026-06-16). Affiliates compromise WordPress sites by credential-stuffing wp-login.php (one victim saw seven residential IPs in an 80-second window) or via WP File Manager CVE-2020-25213, then deploy a PHP backdoor as a must-use plugin (session-manager.php) that injects the ErrTraffic JavaScript. The JavaScript uses the EtherHiding technique (querying Polygon smart contracts via public RPC endpoints) to resolve C2 domains dynamically, defeating takedowns; it then serves ClickFix lures that drop Vidar, Stealc, SmokeLoader and others. ErrTraffic explicitly targets European and APAC visitors, putting public-sector WordPress portals in scope.

Why it matters to us: A reliable hunt artefact is the distinctive PowerShell comment block <# Code Verification: NNNNNNNNNNNN #> Sekoia found at the start of ErrTraffic command strings. Also watch for new PHP files under wp-content/mu-plugins/ (auto-loaded, no activation needed), credential-stuffing bursts on wp-login.php, and outbound requests from the web-server process to blockchain RPC endpoints.

research17 Jun 05:14Zmulti-sourceOpen finding →

explore in graph

Where this entity is cited

  • Research1

Source distribution

  • blog.sekoia.io1 (50%)
  • malwarebytes.com1 (50%)