Hackers are utilizing faux CAPTCHA pages to push a malware loader that may shut down safety software program earlier than a follow-on payload runs.
The marketing campaign combines compromised WordPress web sites, a well-known browser verification immediate, and a Home windows command that victims are persuaded to execute themselves.
The operation makes use of ErrTraffic, a malware supply service that creates ClickFix lures styled as Google reCAPTCHA, Cloudflare Turnstile, or a Home windows error display screen.
A customer who follows the on-screen steps unknowingly runs a copied PowerShell command, opening the door to the Cruciferra loader and the Remus info stealer.
Analysts at eSentire said in a report shared with Cyber Safety Information (CSN) that they recognized a number of ErrTraffic-generated campaigns in late July 2026.
The discovering exhibits how attackers mix polished social engineering with a kernel-level methodology for disabling endpoint protections.
.webp)
The impression is critical as a result of Cruciferra is designed to blind a tool earlier than extra dangerous exercise begins. It abuses a signed however weak driver to terminate chosen antivirus and endpoint detection processes, lowering the prospect that the subsequent stage will probably be stopped or reported.
Hackers Use Pretend CAPTCHA
The assault begins on a respectable WordPress website that attackers have already compromised. An obfuscated JavaScript injection contacts attacker-controlled infrastructure, retrieves the lure, and presents a verification web page that appears routine.
Slightly than exploiting a browser flaw, the web page depends on an individual finishing the attacker’s directions. It copies a malicious PowerShell command to the clipboard and asks the customer to open PowerShell with Home windows Key plus X, paste the command, and run it.
Subsequent PowerShell levels use a respectable Microsoft-signed program to side-load Cruciferra as mscoree.dll.
The loader then makes use of course of hollowing to position the Remus stealer inside ServiceModelReg.exe. Comparable malicious WordPress script injections present why web site homeowners should look ahead to unauthorized modifications.
.webp)
ErrTraffic additionally makes use of Polygon blockchain good contracts to find its present command server. That design lets operators rotate infrastructure with out rewriting the code planted throughout compromised websites.
The service reportedly gives concentrating on filters and templates for Home windows, Linux, and macOS, permitting associates to tailor a lure to the customer and marketing campaign.
The deception follows a broader sample seen in fake CAPTCHA ClickFix campaigns, the place attackers flip a well-known verification immediate right into a malware supply channel. Customers ought to be cautious at any time when a web site asks them to stick textual content right into a Home windows software to finish a CAPTCHA.
Driver Abuse Silences Defenses
Cruciferra’s most regarding characteristic is its potential to load DCRCVDrv.sys, a signed driver with a weak point that lets software program request course of termination from the Home windows kernel.
When the loader is configured with its privilege-bypass and security-killing choices, it writes the motive force to the Home windows Temp listing, creates a service, and begins concentrating on defenses.
Researchers discovered 145 antivirus and EDR-related course of names configured by default. The record consists of merchandise from Microsoft, CrowdStrike, SentinelOne, Sophos, Kaspersky, McAfee, and others.
Killing these processes can take away invaluable warning and containment controls earlier than attackers steal knowledge, unfold by way of a community, or deploy extra malware.
.webp)
This can be a bring-your-own-vulnerable-driver method, during which attackers use an actual signed driver moderately than an clearly malicious kernel part.
It displays the identical danger lined in reporting on driver attacks against EDR, the place a weak driver can provide malware the leverage to neutralize safety software program.
Defenders ought to block the recognized driver by hash of their safety console and maintain Microsoft’s vulnerable-driver protections enabled. Groups must also examine surprising driver providers, browser pages that demand keyboard shortcuts, and PowerShell began instantly after clipboard exercise.
Person consciousness coaching ought to clarify that actual CAPTCHA checks don’t ask folks to stick instructions into Home windows. Organizations ought to deal with a detection of the loader, driver, or listed community infrastructure as a potential lively compromise.
Monitoring for malware disables endpoint defenses is essential as a result of lack of visibility could be the attacker’s first goal.
Indicators of compromise (IoCs):-
| Kind | Indicator | Description |
|---|---|---|
| SHA-256 | 87e8d39db624f37d3e77aedf487a2dfd197f71a4730ea74f4e7a4341deaec2ff |
Weak DCRCVDrv.sys driver |
| SHA-1 | 47d922b0fd5d704025d14ef98ded46e74830a423 |
Weak DCRCVDrv.sys driver |
| MD5 | 567c158ee0858f8e941d4ab7a6c18dbc |
Weak DCRCVDrv.sys driver |
| SHA-256 | 0ae0a7f118b80e4655b8b86bb421c151a8f17930e76e714b2fa199409f3af9ce |
Cruciferra DLL, mscoree.dll |
| Area | makeverizyjar[.]information |
ErrTraffic command-and-control server |
| Area | analysis-id-fmd[.]information |
ErrTraffic command-and-control server |
| Area | analysis-id-lfg[.]information |
ErrTraffic command-and-control server |
| IPv4 | 178.16.52[.]101 |
ErrTraffic command-and-control server |
| Area | karmactive[.]com |
Compromised WordPress website internet hosting an ErrTraffic injection |
| Area | tzpx[.]programs |
Remus command-and-control server |
| Area | zelpx[.]backyard |
Remus command-and-control server |
Notice: IP addresses and domains are deliberately defanged (e.g., [.]) to forestall unintentional decision or hyperlinking. Re-fang solely inside managed risk intelligence platforms corresponding to MISP, VirusTotal, or your SIEM.
Forestall incidents attributable to sluggish investigations. Energy your Tier 1 with risk intelligence from 15K SOCs: Integrate TI Lookup in your SOC