@briankrebs #ErrTraffic to #NetSupportRAT see my quote reply :)

RE: https://infosec.exchange/@briankrebs/116780029181293028

Heads up, Gizmodo has been compromised by some #ErrTraffic affiliate to. Inject is in main response.
ErrTraffic C2 cdnpro-987[.]xyz (Resoved via #EtherHiding)
PS Payload domain cdnportal-us[.]xyz (dynamic PowerShell command URI path)
PowerShell downloads a 16MB encrypted 7z file, checks if 7z is installed and otherwise downloads it to unpack the file and run the contained EXE. The EXE will do some profiling (including refresh rate) and if passes, will drop #NetSupportRAT and run it.
NetSupport C2 178[.]16[.]55[.]191.

TA also has a Mac payload configured, but it seems broken at the moment and ask for a password of some zip file when executed đŸ€·

Note: ErrTraffic is a ClickFIx-as-a-Service, so other compromised sites can lead to other malware from other affiliates.

We published an in-depth analysis on the #ErrTraffic framework, detailing two specific clusters ("Beer" and "Analytics"), campaigns compromising WordPress sites to deploy this malicious #ClickFix framework, as well as others impersonating AI platforms

Since that report was written, the operator "LenAI" has released ErrTraffic v4.

We shared some IoCs on our Community GitHub, and and I can share the latest ones, feel free to reach out!

https://github.com/SEKOIA-IO/Community/tree/main/IOCs/errtraffic

https://infosec.exchange/@sekoia_io/116758846525821124

Community/IOCs/errtraffic at main · SEKOIA-IO/Community

Welcome to the SEKOIA.IO Community repository! . Contribute to SEKOIA-IO/Community development by creating an account on GitHub.

GitHub

#TDR analysts published a new report detailing #ErrTraffic, a widespread #ClickFix malware distribution framework.

ErrTraffic injects malicious JavaScript into compromised WordPress and malicious sites to serve ClickFix lures.

https://blog.sekoia.io/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework/

Err-Hiding and Seek: How ErrTraffic v3 Leverages EtherHiding in ClickFix Campaign

The LevelBlue SpiderLabs team examined the latest version of ErrTraffic, which emerged in early 2026.

📱 ErrTraffic v2 industrialise les leurres « ClickFix » avec des taux d’infection proches de 60%
📝 Selon Hudson Rock, une nouvelle suite criminelle baptisĂ©e ErrTraffic v2, promue sur des forums cyb...
📖 cyberveille : https://cyberveille.ch/posts/2025-12-29-errtraffic-v2-industrialise-les-leurres-clickfix-avec-des-taux-dinfection-proches-de-60/
🌐 source : https://www.infostealers.com/article/the-industrialization-of-clickfix-inside-errtraffic/
#ClickFix #ErrTraffic #Cyberveille
ErrTraffic v2 industrialise les leurres « ClickFix » avec des taux d’infection proches de 60%

Selon Hudson Rock, une nouvelle suite criminelle baptisĂ©e ErrTraffic v2, promue sur des forums cybercriminels russophones, industrialise les leurres « ClickFix » afin d’amener les utilisateurs Ă  exĂ©cuter eux-mĂȘmes des scripts malveillants via Win+R/PowerShell, contournant ainsi les protections des navigateurs et d’EDR. ⚙ Points saillants: outil vendu 800 $, taux de conversion jusqu’à 58,8%, usage de « faux glitches » (artefacts visuels/texte corrompu) pour crĂ©er l’urgence, ciblage multi-OS (Windows, macOS, Android, Linux) et exclusion CIS (BY, KZ, RU, etc.). Le tableau de bord montre 34 vues, 20 « downloads » et 58,8% de conversion sur une campagne test.

CyberVeille