ErrTraffic and Cruciferra: Malware-as-a-Service ClickFix Delivery Paired With a Kernel-Mode EDR Killer
Source report →In late July 2026, an incident response investigation identified multiple ClickFix campaigns generated by the ErrTraffic Malware-as-a-Service platform being used to deliver payloads packed by a second, unrelated service called Cruciferra. Both services are sold on Russian-speaking underground forums, with ErrTraffic providing delivery and Cruciferra offering payload execution and endpoint security evasion. Cruciferra has been advertised since November 2025 in two tiers: a side-loaded DLL capable of terminating antivirus and EDR processes, and a standalone executable that adds Windows Defender exclusions. Operators provide their own final-stage malware, which in the observed campaigns was the Remus information stealer.
Initial access begins on compromised WordPress sites injected with an obfuscated JavaScript loader. The obfuscated script uses Base64 encoding and single-byte XOR encryption. Once decoded, it queries a Polygon smart contract to resolve the active command-and-control domain and loads the lure from that server. The lure impersonates Google reCAPTCHA, Cloudflare Turnstile, or a Windows blue-screen error, then copies a PowerShell command to the victim’s clipboard and instructs them to open a terminal from the Windows Quick Link menu and execute it. Additional PowerShell stages ultimately launch a legitimate Microsoft-signed executable that side-loads the Cruciferra DLL, which injects Remus into a hollowed Microsoft-signed process.
Cruciferra performs privilege escalation and defense evasion primarily through the Windows API, avoiding command-line utilities. It resolves required APIs from kernel32.dll and ntdll.dll using custom export hashing and decrypts embedded strings at runtime. When enabled by the operator, the loader requests elevation through the COM elevation moniker and deploys an embedded copy of DCRCVDrv.sys to a system temporary directory, registers it as a service, and opens a handle to the driver. It then enumerates running processes and sends matching process IDs to the driver through a device control request. The driver terminates them from kernel mode, targeting 145 antivirus and EDR process names across more than 30 vendors, with support for additional custom targets configured through the Cruciferra panel.
ErrTraffic stores its active command-and-control domain in two Polygon smart contracts, which the injected script queries through fourteen public blockchain RPC providers for redundancy. Operators periodically update the domain on-chain, propagating the change across all compromised websites without modifying the injected JavaScript. Because this lookup occurs in the victim’s browser, both the blockchain request and the initial connection to attacker infrastructure appear as browser activity. Despite frequent domain rotation, the underlying hosting is comparatively stable. A single IP address, 178.16.52[.]101, hosted more than 170 campaign domains between February and August 2026. The ErrTraffic panel also provides geographic and referrer filtering, campaign statistics, and a WordPress plugin generator, while Cruciferra offers optional EV certificate signing and payload padding alongside its packing service.
IOCs (179)
Scan your environment for IOCs →SHA256 FILE HASH 2
0ae0a7f118b80e4655b8b86bb421c151a8f17930e76e714b2fa199409f3af9ce87e8d39db624f37d3e77aedf487a2dfd197f71a4730ea74f4e7a4341deaec2ffSHA1 FILE HASH 1
47d922b0fd5d704025d14ef98ded46e74830a423MD5 FILE HASH 1
567c158ee0858f8e941d4ab7a6c18dbcDOMAIN 174
makeverizyjar[.]infoanalysis-id-fmd[.]infoanalysis-id-lfg[.]infokarmactive[.]comtzpx[.]courseszelpx[.]gardenfingerprint-verification[.]infoverico-de-id[.]beermsn00273[.]beerenter-press-code[.]infoverif-key-code[.]infoid-verif-code[.]infoenter-pverif-code[.]infoenter-press-cdn[.]infoenter-code-cdn[.]infoauthorization-code-cdn[.]infoauthorization-id-browser[.]infoauth-id-browser[.]infoauth-code-verif[.]beerauth-code-check[.]infoauthorization-press-enter[.]infoauthorization-cdn-press-enter[.]infoauthorization-id-code[.]infoauthorization-code[.]infoauthorization-code[.]beercodeverificatrorcl[.]infoidverification-cdn[.]infoverificationscodes[.]beerverification-claude-cdn[.]beerclaudverification-id[.]beeridverification-code[.]beercodecerification[.]beercode-verification-js[.]beerverification-code-js[.]beersvs-verificationdate[.]beercdn-verification-cloud[.]boatsverification-js-cdn[.]boatsframework-css-styles-js[.]beerethercdnns[.]beerclhfgcomacdn[.]beerladydosug[.]loveladydosug[.]liveladydosug[.]topistounscnnd[.]beertrunnsns[.]beermstclaudens[.]beerxdavnode[.]prohftplcnsns[.]beerlskannsserv[.]beerhasmeverdcdn[.]beerclaufancdn[.]beersrtydnnc[.]beerbhfgtrns-js[.]beertescdnlast[.]beersmfcdnbb[.]beershssshdscn[.]beersnccdn-framework[.]beertestapi34726[.]sbsnstdcs[.]beerframework-jsoncdn[.]beergppcdnns[.]beerhpscdn[.]beernvbfcdnclaud[.]beerlnfcdnclad[.]beerclainasns[.]beernshtjscdn[.]beernfstsrcdn[.]beergdnssljs[.]beerbiyaconserver[.]beernpanssltejs[.]beerbootstrup-framework-js[.]beernshostvps[.]beerchekbrow[.]beersmtnscerver[.]beersns-clauder-cdn[.]beeranlytic-js-cloud[.]beervisual-ns-portal[.]beerslndcdnclaud[.]beerbootstrup-cdnmaper[.]beernsserv-bootstru[.]beerns1cdnclaude[.]beerslngftr[.]beertravel-js-ns[.]beersmetana-js[.]beermistraljs[.]beerlsikjsns[.]beerssns-cdn-ns[.]beersane-cdn-js[.]beersr-hostes-js[.]beerdarndcs-js[.]beerbkscndclou[.]beerbcncdncl-ns[.]beerviscdnclaud[.]beerldnscreatejs[.]beertesterlau[.]latnfsclaudecdn[.]beerssjscrybootstrup[.]beerclacndjsvulnarbi[.]beerlas-js-claud[.]beerclaudjaframework[.]beerframesavecloudjs[.]beerolnsclaud[.]beerframeworkjsbns[.]beernsserdns[.]beerclaudesave[.]beernsbdnscloud[.]beercloude-js-server[.]beerbest-claudns-js[.]beerawesomeisojs[.]beerns-claude-js[.]beerntsnsdns[.]beervjscloudjsns[.]beernslsconscloud[.]beerns-server-jscdn[.]beerlcstdnsns[.]beercloudcdnginx[.]beerbootstrap-maxcdn[.]beerdhnsdns[.]beerfijscdn[.]beerbootstrup-cdn-ns[.]beerbbdsnssserver[.]beerlsnsdns[.]beerfontawesome-js-cdn[.]beerbilfojsclod[.]beerdreff-nsdns[.]beervsactivens[.]beerjsframeworkns[.]beernsservclod[.]beerclnsdns[.]beerbnnsbdsdn-js[.]beerpolygon-date[.]beermnoskemp[.]beerbnsclod[.]beervnmstokns[.]beerghdnsserverns[.]beersmnsdns[.]beersssndns[.]beervnmdnns[.]beerneiwteamcdn[.]beercgfuryclaud[.]shopexdanteam[.]beerl3cdnns[.]beerlenteam[.]beerdncloteam[.]beersdnssmdf-js[.]beervsbnsbootstrup[.]beerteamcss[.]beersiteamnsserv[.]beerwpteamcdn[.]beerjs-server[.]beerlndteam[.]beersdhscndnssl[.]beerstabcdnvlc[.]beerlckcdnjs[.]beerworkcdnmass[.]beercapcha-cdn-js[.]beercdn-plugin-js[.]beerssg-cdn[.]beerrpc-cloud[.]beerlocalcloudcss[.]sbscdn-yethounds[.]beerverification-cdn-cloud[.]beerlcates-vs[.]beercloud-save-image[.]sbsvirtual-cdncloud[.]sbswinecdn[.]sbscdn-2faclov[.]sbsmandare[.]liferpc-polygon[.]beerstr-smcontrcats[.]cfdai-nexora[.]sbsall-imager-hst[.]clickstore-image[.]shopnexus-server[.]clickIP ADDRESS 1
178.16.52[.]101Detections (8)
Enable detections →Connect your environment for suggestions and queries personalized to your security telemetry.
- Browser Process Resolving a Public Blockchain RPC Endpoint
- Known Sideloading Target Library Loaded From a User Writable Directory
- Interactive Shell Spawning an Interpreter With a Remote Fetch Cradle
- DCRCVDrv Vulnerable Kernel Driver Written to a System Temporary Directory
- Kernel Driver File Written Into a System Temporary Directory
- Loss of Multiple Endpoint Security Agent Processes Without a Stop or Uninstall Command
- Auto-Elevating COM Server Instantiated by a Process Running From a User-Writable Path