---
schema: 1
kind: research
title: "Sekoia: ErrTraffic — a ClickFix Malware-as-a-Service framework resolving C2 through the Polygon blockchain"
headline: "Sekoia: ErrTraffic — a ClickFix Malware-as-a-Service framework resolving C2 through the Polygon blockchain"
summary: "ClickFix — fake browser/update dialogues that trick users into pasting attacker PowerShell — is maturing into a productised delivery channel, as this and the next item show."
discovered_at: "2026-06-17T05:14:29Z"
event_date: 2026-06-16
run_id: 2026-06-17-e102009c
priority: notable
immediate_action: null
tags:
  - supply-chain
  - infostealer
  - phishing
  - cryptocrime
regions:
  - europe
  - apac
sectors:
  - public-sector
  - education
  - media
entities:
  - "campaign:sekoia-errtraffic-clickfix-maas-polygon-c2"
cves: []
sources:
  - url: "https://blog.sekoia.io/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework/"
    publisher: "Sekoia TDR, 2026-06-16"
    role: primary
  - url: "https://www.malwarebytes.com/blog/threat-intel/2026/06/inside-a-malicious-infrastructure-delivering-etherrat-phishing-pages-and-malicious-software"
    publisher: "Malwarebytes Labs, 2026-06"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: "migration: CVE fields incomplete in v2 footer (CVE-2020-25213)"
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-17.md
---

ClickFix — fake browser/update dialogues that trick users into pasting attacker PowerShell — is maturing into a productised delivery channel, as this and the next item show. Sekoia's TDR team analysed ErrTraffic, a ClickFix distribution framework sold as MaaS by an actor using the handle "LenAI" on the Exploit.IN forum since at least December 2025 ([Sekoia TDR, 2026-06-16](https://blog.sekoia.io/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework/)). Affiliates compromise WordPress sites by credential-stuffing `wp-login.php` (one victim saw seven residential IPs in an 80-second window) or via WP File Manager `CVE-2020-25213`, then deploy a PHP backdoor as a must-use plugin (`session-manager.php`) that injects the ErrTraffic JavaScript. The JavaScript uses the EtherHiding technique — querying Polygon smart contracts via public RPC endpoints — to resolve C2 domains dynamically, defeating takedowns; it then serves ClickFix lures that drop Vidar, Stealc, SmokeLoader and others. ErrTraffic explicitly targets European and APAC visitors, putting public-sector WordPress portals in scope.

**Why it matters to us:** A reliable hunt artefact is the distinctive PowerShell comment block `<# Code Verification: NNNNNNNNNNNN #>` Sekoia found at the start of ErrTraffic command strings. Also watch for new PHP files under `wp-content/mu-plugins/` (auto-loaded, no activation needed), credential-stuffing bursts on `wp-login.php`, and outbound requests from the web-server process to blockchain RPC endpoints.
