A malware-as-a-service (MaaS) marketing campaign has mixed ClickFix social engineering with the ErrTraffic supply service and Cruciferra loader, giving attackers a option to distribute malware whereas disabling endpoint safety processes.
In a brand new advisory printed earlier at this time, eSentire’s Menace Response Unit (TRU) described a number of ErrTraffic-generated ClickFix campaigns noticed in late July 2026 that tried to ship Cruciferra.
The loader is marketed on underground boards with options designed to kill antivirus and endpoint detection and response (EDR) processes.
Turning Compromised Websites Into ClickFix Supply Platforms
The marketing campaign started with compromised WordPress websites containing an obfuscated ErrTraffic JavaScript injection.
The script used the Ethereum blockchain to resolve a command-and-control (C2) handle earlier than retrieving JavaScript for a pretend Google reCAPTCHA, Cloudflare Turnstile or Blue Display of Demise (BSOD) lure.
The lure copied a malicious PowerShell command to the sufferer’s clipboard and instructed them to stick and run it.
Further PowerShell levels then used a official Microsoft-signed binary to sideload the Cruciferra DLL, which used course of hollowing to inject the Remus data stealer right into a second Microsoft-signed binary, ServiceModelReg.exe.
Compromised WordPress websites have beforehand been used to deliver ClickFix malware, however the eSentire marketing campaign mixed the method with two separate MaaS choices.
ErrTraffic was marketed for $380 monthly and offered operators with customizable ClickFix templates, marketing campaign statistics, filtering and a WordPress plugin generator. Its use of blockchain-based infrastructure additionally allowed operators to rotate C2 domains with out altering the JavaScript injected into compromised web sites.
Cruciferra’s EDR-killing bundle price $1,200 monthly and is marketed as a loader able to disabling safety merchandise.
The payload abused the signed susceptible DCRCVDrv.sys driver to terminate security-related processes from the Home windows kernel. eSentire discovered 145 course of names configured for termination by default, most of them antivirus and EDR merchandise.
The driving force is just not at the moment recognized to Microsoft or LOLDrivers, which means it is not going to be caught by the susceptible driver blocklist. eSentire really helpful blocking it straight by hash.
Read more on EDR-killing techniques: Ransomware Groups Increasingly Deploy EDR Kill Technique
The marketing campaign confirmed how operators may mix separate MaaS merchandise to outsource supply, social engineering and protection evasion quite than growing every functionality themselves.