New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
Sekoia says the Exvicy ClickFix malware service reuses ErrTraffic code and delivers payloads via WordPress.
Sekoia's Threat Detection and Research team reported that Exvicy, a ClickFix malware-as-a-service, reuses code from rival service ErrTraffic and is already delivering malware. A Russian-speaking operator advertising as Exvicy has sold it on Exploit.in since May 26, raising the price from $1,200 to $2,000 a month by mid-August. Compromised WordPress sites inject obfuscated JavaScript that shows a fake Cloudflare Turnstile check and tells victims to press Win+R and run a PowerShell command copied to the clipboard. Sekoia found customer hosts talking to Exvicy C2 servers and about 80 panel hosts by late August; unlike ErrTraffic's EtherHiding, Exvicy hardcodes two servers.