A recent malware-as-a-service (MaaS) campaign has come to light, illustrating a sophisticated blend of social engineering tactics with advanced distribution methods. This initiative merges ClickFix social engineering techniques with the ErrTraffic delivery service and the Cruciferra loader, creating a potent tool for cybercriminals to disseminate malware while effectively evading endpoint security measures.
In a newly released advisory, eSentire’s Threat Response Unit (TRU) has detailed multiple campaigns utilizing ErrTraffic-generated ClickFix tactics observed in late July 2026 that focused on delivering the Cruciferra malware. This loader has gained attention in underground forums, where it is advertised with features specifically designed to terminate antivirus and endpoint detection and response (EDR) processes.
### Compromised Sites as Delivery Mechanisms
The inception of this campaign was marked by the exploitation of compromised WordPress sites. Attackers injected an obfuscated ErrTraffic JavaScript code into these platforms, allowing them to leverage the Ethereum blockchain to resolve a command-and-control (C2) address. This facilitated the retrieval of JavaScript for various deceptive techniques, including fake Google reCAPTCHA forms, Cloudflare Turnstile prompts, and even a luring Blue Screen of Death (BSOD) message.
The malicious script employed in this scheme was designed to manipulate the victim into copying a malicious PowerShell command to their clipboard and then encouraged them to paste and execute it. By doing so, additional stages of PowerShell were triggered, employing a legitimate Microsoft-signed binary to sideload the Cruciferra DLL. This DLL was utilized to perform process hollowing, injecting the Remus information stealer into another legitimate Microsoft-signed binary, ServiceModelReg.exe.
Historically, compromised WordPress sites have been used to deliver ClickFix malware; however, the unique approach taken in this eSentire campaign effectively combined the efforts of two distinct MaaS offerings.
### The Tools of Cybercrime
The ErrTraffic service itself is offered at a price point of $380 per month, providing operators with customizable ClickFix templates and campaign statistics, alongside a WordPress plugin generator. One notable feature of ErrTraffic is its blockchain-based infrastructure, enabling operators to seamlessly rotate C2 domains without altering the JavaScript code injected into compromised websites.
On the other hand, Cruciferra, with an EDR-killing module available for $1,200 per month, has been marketed as a loader specifically engineered to thwart existing security systems. Its payload exploits the vulnerabilities in the signed DCRCVDrv.sys driver, effectively terminating security-related processes directly from the Windows kernel. eSentire’s findings revealed that this malicious tool was pre-configured to target 145 process names, the majority of which are associated with antivirus and EDR products, thereby demonstrating a calculated approach to disable defenses.
Adding to the complexity of this attack vector, the driver itself is not recognized by Microsoft or LOLDrivers, indicating that it will evade detection by the existing vulnerable driver blocklist. In light of these developments, eSentire has advised organizations to take proactive measures by directly blocking this driver based on its hash value.
### The Broader Implications
The strategic coordination highlighted in this malware campaign underscores the evolving landscape of cyber threats, as operators are increasingly able to amalgamate different MaaS products to effectively manage the delivery of malware, social engineering tactics, and methods to evade detection. This psychological aspect adds a layer of complexity to the existing cybersecurity challenges, emphasizing the need for organizations to enhance their protective measures.
As cybercriminals continue to innovate and refine their strategies, the imperative remains for businesses to stay informed and vigilant against such sophisticated attacks. The interplay of technological advancements in cybercrime attempts necessitates a proactive and comprehensive approach to cybersecurity, where organizations must not only react but also anticipate potential threats before they manifest into successful breaches.
For deeper insights into the prevalence and techniques associated with EDR-killing methods, there remains a call in security circles to remain abreast of evolving threats, particularly as ransomware groups demonstrate a growing inclination toward employing such evasion tactics. The ongoing battle between cybersecurity professionals and cybercriminals will only intensify as technology continues to evolve in both offensive and defensive aspects.

