Executive Summary
ErrTraffic is a maturing Malware-as-a-Service (MaaS) framework, primarily operated by the threat actor LenAI, that facilitates the distribution of malware via 'ClickFix' lures (deceptive browser/system error messages). The system leverages the EtherHiding technique, using smart contracts on the Polygon blockchain as Dead Drop Resolvers to hide C2 infrastructure and evade detection.
Research has identified two primary operational clusters: 'Analytics' and 'Beer.' The 'Analytics' cluster appears to be a single-actor campaign consistently delivering Vidar infostealers through a proprietary PHP backdoor. Conversely, the 'Beer' cluster operates as a multi-affiliate MaaS, hosting various payloads such as DanaBot and Stealc, and utilizing diverse infection vectors including malicious sites impersonating AI platforms like ChatGPT and Google Antigravity.
This threat is significant due to its industrialization of credential theft and its ability to rotate infrastructure via blockchain, making traditional IP/domain blocking less effective. Organizations should prioritize securing WordPress instances and monitoring for unusual PowerShell activity triggered by web browser interactions.
Key Details
Threat Name
ErrTraffic ClickFix Framework
Affects
WP File Manager
Adversary
LenAI Other Adversaries and Aliases: tope; APT28
Malware/Tools
ErrTraffic, Vidar, DanaBot, HijackLoader, Stealc, Remus, Salat, SmokeLoader, Responsive Webshell, session-manager.php
