LIVE · cybersecurity feed
Live wire
'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllersNSA, FBI warns of hackers using AI-generated tools in attacks on critical infrastructure technologyUS warns of AI-powered attacks on Siemens PLCs in critical infrastructureCVE-2026-19490 · CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler GatewayA California county wants to hire Tina Peters to help run its electionsThe long tail of Clop’s PTC hack is just beginning to emergeOracle Critical Patch Update, August 2026 Security Update ReviewMedusa ransomware gang has hit over 500 organizations, CISA warnsCritical RCE flaw in Windows IKE Extension now actively exploitedOracle August 2026 Critical Security Patch Update Addresses 925 CVEs
malware

MaaS Campaign Combines ClickFix, ErrTraffic and Cruciferra

eSentire uncovered a malware campaign combining ClickFix lures with ErrTraffic and Cruciferra

zeroday.news ·

A new malware-as-a-service (MaaS) campaign has been identified that integrates three distinct services: ClickFix for social engineering, ErrTraffic for malware delivery, and Cruciferra as a loader. This combination allows attackers to distribute malware while simultaneously disabling endpoint security measures.

The eSentire Threat Response Unit (TRU) detailed several ErrTraffic-generated ClickFix campaigns observed in late July 2026, which aimed to deliver the Cruciferra loader. Cruciferra is advertised on underground forums for its ability to terminate antivirus and endpoint detection and response (EDR) processes.

The campaign starts with compromised WordPress sites that have an obfuscated ErrTraffic JavaScript injection. This script leverages the Ethereum blockchain to resolve a command-and-control (C2) address. Subsequently, it retrieves additional JavaScript to display a fake lure, such as a Google reCAPTCHA, Cloudflare Turnstile, or a Blue Screen of Death (BSOD).

Victims are then instructed to copy a malicious PowerShell command, which is placed on their clipboard by the lure, and execute it. Further PowerShell stages utilize a legitimate Microsoft-signed binary to sideload the Cruciferra DLL. Cruciferra then employs process hollowing to inject the Remus information stealer into another Microsoft-signed binary, ServiceModelReg.exe.

ErrTraffic, which costs $380 per month, offers operators customizable ClickFix templates, campaign statistics, filtering capabilities, and a WordPress plugin generator. Its use of blockchain-based infrastructure enables operators to rotate C2 domains without needing to alter the JavaScript injected into compromised websites.

Cruciferra, priced at $1,200 per month, is marketed as a loader designed to disable security products. It achieves this by abusing the signed vulnerable driver DCRCVDrv.sys to terminate security-related processes from the Windows kernel. eSentire discovered that Cruciferra is configured by default to terminate 145 process names, primarily those associated with antivirus and EDR products.

The DCRCVDrv.sys driver is not currently known to Microsoft or listed in the LOLDrivers database, meaning it will not be blocked by existing vulnerable driver blocklists. eSentire recommends blocking this driver directly by its hash.

This campaign highlights a growing trend where operators combine separate MaaS products to outsource various aspects of an attack, including delivery, social engineering, and defense evasion, rather than developing these capabilities in-house.

malwarepatch
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Smashing Security podcast #481: Never say this to a robot dog

At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold stat

aicritical

'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers

'It is an active threat'

ransomware

Rogue ransomware affiliate poses as data recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]

cloud

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]

breach

Healthtech firm CareCloud data breach impacts 3.7 million patients

U.S. healthcare IT company CareCloud disclosed that the data breach incident it suffered earlier this year has impacted more than 3.7 million individuals. [...]

ai

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first. The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.