Unveiling ErrTraffic ClickFix Malware Distribution Framework
Score: 9/10

Unveiling ErrTraffic ClickFix Malware Distribution Framework

The ErrTraffic framework utilizes the ClickFix social engineering tactic and EtherHiding technique to distribute various infostealers and loaders through compromised WordPress sites and AI-themed lures.

Executive Summary

ErrTraffic is a maturing Malware-as-a-Service (MaaS) framework, primarily operated by the threat actor LenAI, that facilitates the distribution of malware via 'ClickFix' lures (deceptive browser/system error messages). The system leverages the EtherHiding technique, using smart contracts on the Polygon blockchain as Dead Drop Resolvers to hide C2 infrastructure and evade detection.

Research has identified two primary operational clusters: 'Analytics' and 'Beer.' The 'Analytics' cluster appears to be a single-actor campaign consistently delivering Vidar infostealers through a proprietary PHP backdoor. Conversely, the 'Beer' cluster operates as a multi-affiliate MaaS, hosting various payloads such as DanaBot and Stealc, and utilizing diverse infection vectors including malicious sites impersonating AI platforms like ChatGPT and Google Antigravity.

This threat is significant due to its industrialization of credential theft and its ability to rotate infrastructure via blockchain, making traditional IP/domain blocking less effective. Organizations should prioritize securing WordPress instances and monitoring for unusual PowerShell activity triggered by web browser interactions.

Key Details

Threat Name

ErrTraffic ClickFix Framework

Affects

WP File Manager

Adversary

LenAI Other Adversaries and Aliases: tope; APT28

Malware/Tools

ErrTraffic, Vidar, DanaBot, HijackLoader, Stealc, Remus, Salat, SmokeLoader, Responsive Webshell, session-manager.php

Report Score

9out of 10
Quality Score
Excellent
IOC Quality8
TTP Details9
Detection Guidance8
Enterprise Relevance9
Clarity & Structure10
Technical Depth9

Sources