Skip to main content
Mallory
MalwareUsed by 1 actorExploits 1 CVE

ErrTraffic

ErrTraffic is a Malware-as-a-Service (MaaS) traffic distribution framework used to automate ClickFix social-engineering attacks and distribute malware. It is primarily associated with malicious JavaScript injected into compromised websites, especially WordPress sites, where it displays fake browser or system error lures such as BSOD, reCAPTCHA, Cloudflare verification, browser, font, and update-themed prompts. Victims are induced to copy and execute malicious commands, including clipboard-delivered PowerShell, resulting in payload delivery. ErrTraffic has been advertised on Russian-speaking underground forums since at least late 2025 by the actor LenAI and has been described as a self-hosted TDS sold commercially.

Observed campaigns show ErrTraffic primarily targeting compromised WordPress environments. Attackers used stolen administrator credentials to access sites and deployed persistent PHP backdoors, including a malicious must-use plugin named session-manager.php. Reported backdoor capabilities include credential harvesting, persistence, anti-detection logic, visitor analytics beacons, multiple webshell channels, and in some cases WooCommerce skimming. Malicious JavaScript was injected into page footers or served via endpoints such as /cf.js and /api/css.js. ErrTraffic supports geofiltering, OS detection, multilingual lures, and selective victim targeting, and has been reported to support payload delivery across Windows, macOS, Android, and Linux.

A notable feature of ErrTraffic is its use of EtherHiding and Polygon blockchain smart contracts as a dead-drop resolver to conceal and rotate command-and-control infrastructure. Researchers observed the framework querying Polygon RPC endpoints and smart contracts, including use of wallet address 0x08207B087F61d7e95E441E15fd6d40BEfd6eD308 and the getURL() selector 0x38bcdc1c, to retrieve attacker-controlled infrastructure. Backend communications and payload delivery have been reported as encrypted using AES-GCM or RC4 depending on cluster or version.

Research identified at least two operational clusters, referred to as Analytics and Beer. The Analytics cluster was associated with WordPress compromises, persistent MU-plugin backdoors, credential theft, analytics beacons to webanalytics-cdn domains, and Vidar delivery. The Beer cluster used multiple smart contracts, often .beer domains, and delivered a broader range of malware including Vidar, Stealc, Remus, Salat, SmokeLoader, DanaBot, HijackLoader, RATs, and other loaders. Fake AI-themed sites were also used in some campaigns, including antigravity[.]study impersonating Google Antigravity and chatgpt-web[.]vip impersonating ChatGPT.

High-confidence indicators mentioned in the content include domains such as travel-js-ns.beer, vsactivens.beer, clip-stash.beer, js-server.beer, ns-claude-js.beer, ponikas.cyou, nextpgh3.com, abrikos.xyz, pohuimne.lol, microchlen.lat, webanalytics-cdn.icu, webanalytics-cdn.cyou, webanalytics-cdn.sbs, webanalytics-cdn.cfd, and traffadmin.monster; the URL https://devltd.top/flomowk2.zip; and hashes MD5 1f5a7f45c9ad8f06b9bf1ddc2a99c8fa, SHA-1 0f769f459f9ed3e02c3d76af39dafc4e944f871b, and SHA-256 83264e9216fb747d9e0048c6559d66dfca05cf50a1d415ecf212c879d08741ce.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2020-25213Arbitrary File Upload in WordPress File Manager Plugin (wp-file-manager) < 6.9

ErrTraffic is a malicious JavaScript framework primarily injected into compromised WordPress sites to display the ClickFix lure and subsequently deliver malware to visitors.

via sekoia blogblog.sekoia.io
THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
LenAI

ErrTraffic is a malicious JavaScript framework primarily injected into compromised WordPress sites to display the ClickFix lure and subsequently deliver malware to visitors.

via sekoia blogblog.sekoia.io
MITRE ATT&CK

Techniques & procedures

14 distinct techniques documented for this family, organized by ATT&CK tactic.

Resource Development

1 technique
T1584Compromise InfrastructureEvidence2

ClickFix social engineering lures embedded in compromised WordPress websites... Analysis revealed multiple operational clusters, malicious WordPress plugins...

Initial Access

2 techniques
T1189Drive-by CompromiseEvidence2

ErrTraffic is a Malware-as-a-Service (MaaS) framework used to distribute malware through ClickFix social engineering lures embedded in compromised WordPress websites.

T1566.002Spearphishing LinkEvidence2

The framework incorporates a Traffic Distribution System (TDS) and uses EtherHiding to conceal its command-and-control infrastructure within the blockchain... campaigns leveraging fake AI-themed websites to deliver malware at scale.

Execution

1 technique
T1059.001PowerShellEvidence1

The retrieved payload contains an obfuscated PowerShell payload that is automatically encrypted using unique XOR keys... This PowerShell Script will be attached to the user’s clipboard once the ClickFix lure is loaded.

Persistence

2 techniques
T1205Traffic SignalingEvidence3

The framework incorporates a Traffic Distribution System (TDS)...

T1505.003Web ShellEvidence1

ErrTraffic primarily targets WordPress websites by deploying a PHP backdoor script in the must-use plugin (mu-plugin) that captures administrator credentials and ensures persistence on compromised sites.

Stealth

3 techniques
T1027Obfuscated Files or InformationEvidence1

On the infected website, the backdoor injects malicious inline scripts that leverage both XOR and Base64 obfuscation to evade detection.

T1205Traffic SignalingEvidence3

The framework incorporates a Traffic Distribution System (TDS)...

T1497.001System ChecksEvidence1

The use of multilingual content and environment-aware targeting further strengthens these lures by adapting the message based on the visitor’s browser language, operating system, and environment

Credential Access

1 technique
T1539Steal Web Session CookieEvidence1

the team found that ErrTraffic primarily targets WordPress websites by deploying a PHP backdoor script in the must-use plugin (mu-plugin) that captures administrator credentials

Discovery

1 technique
T1497.001System ChecksEvidence1

The use of multilingual content and environment-aware targeting further strengthens these lures by adapting the message based on the visitor’s browser language, operating system, and environment

Collection

1 technique
T1115Clipboard DataEvidence1

This PowerShell Script will be attached to the user’s clipboard once the ClickFix lure is loaded.

Command and Control

5 techniques
T1071Application Layer ProtocolEvidence1

The framework ... uses EtherHiding to conceal its command-and-control infrastructure within the blockchain.

T1071.001Web ProtocolsEvidence1

The script communicates with the server API by specifying an action type in the “a” parameter... cfg : Fetches the latest configuration. dl : Fetches the latest payload.

T1105Ingress Tool TransferEvidence1

After being triggered, the script forces the use of TLS 1.2, creates a randomly named directory and executable file in the system’s temporary folder, and attempts multiple times to retrieve the payload from the attacker-controlled endpoint.

T1205Traffic SignalingEvidence3

The framework incorporates a Traffic Distribution System (TDS)...

T1568Dynamic ResolutionEvidence1

ErrTraffic initially calls the getUrlFromContract() function to retrieve the command-and-control (C2) panel domain from a blockchain smart contract. Instead of hardcoding the server address directly in the script, the malware queries multiple Polygon RPC endpoints

INDICATORS OF COMPROMISE

IOCs tracked for this family

81 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
72 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
7 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
2 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
domain●●●●●●●●●●●●View more in apptoday
ACTIVITY FEED

Recent activity

12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

gurucul threat researchNews
Jun 17, 2026
Unveiling ErrTraffic: Inside a Growing ClickFix Malware Distribution Framework | Community Portal | Gurucul

A malware distribution framework operated as MaaS that uses ClickFix lures on compromised WordPress sites, includes a TDS component, and hides C2 infrastructure via EtherHiding in the blockchain to deliver malware at scale.

Read more
sekoia blogNews
Jun 16, 2026
Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework - Sekoia.io Blog

A malicious JavaScript framework and TDS sold as a MaaS offering. It is injected into compromised WordPress sites or attacker-controlled lure sites, uses ClickFix social engineering and EtherHiding/Polygon smart contracts to resolve C2 infrastructure, and delivers follow-on payloads to victims.

Read more
levelblueNews
Apr 9, 2026
Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign

A multi-platform traffic distribution system built for ClickFix campaigns. It compromises WordPress sites with a PHP backdoor, injects obfuscated JavaScript, uses blockchain-based EtherHiding to retrieve attacker-controlled infrastructure, filters and redirects visitors to ClickFix lures, and delivers OS-specific payloads for Windows or macOS.

Read more
the hacker newsNews
Feb 26, 2026
Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown

Crimeware toolkit used to automate ClickFix-style social engineering by generating fake website glitches to pressure users into following malicious instructions.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching81

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping14

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.