Exvicy ClickFix Malware-as-a-Service Built on Rival ErrTraffic's Code, Sekoia Says
Sekoia assesses with high confidence that Exvicy, a ClickFix malware-as-a-service sold on Exploit.in since May 26 and now priced at $2,000 a month, is a copycat of ErrTraffic that delivers clipboard-based PowerShell payloads through fake Cloudflare Turnstile…
Sekoia's Threat Detection and Research team, in a technical write-up published September 21, 2026, reported that Exvicy — a new ClickFix malware-as-a-service (MaaS) — is already delivering malware and assesses with high confidence that it is a copycat of the rival ErrTraffic framework, reusing its JavaScript injection and C2 routines. A Russian-speaking operator advertising as Exvicy has sold the service on the Exploit.in forum since May 26, raising the subscription price from $1,200 to $2,000 a month by mid-August. The attack chain works by injecting obfuscated JavaScript into compromised WordPress sites; victims see a fake Cloudflare Turnstile verification check and are told to press Win+R and run a PowerShell command that has been silently copied to their clipboard, with the lure localized in 13 languages. Sekoia telemetry from customer environments showed hosts communicating with Exvicy command-and-control (C2) servers, confirming real-world use by threat actors, and the researchers tracked roughly 80 hosts serving the Exvicy admin panel by late August. A notable technical difference from ErrTraffic: while ErrTraffic relies on EtherHiding, Exvicy hardcodes two C2 servers directly in its scripts. The two sources are consistent, with GBHackers (September 23) corroborating Infosecurity Magazine's (September 21) account of the Sekoia findings.
- Sekoia's Threat Detection and Research team assesses with high confidence that Exvicy is a copycat of ErrTraffic, reusing its JavaScript injection and C2 routines.
- A Russian-speaking operator advertising as Exvicy has sold the MaaS on the Exploit.in forum since May 26.
- The subscription price rose from $1,200 to $2,000 a month between late May and mid-August.
- Compromised WordPress sites inject obfuscated JavaScript that displays a fake Cloudflare Turnstile verification check.
- Victims are instructed to press Win+R and run a PowerShell command copied to their clipboard; the lure is presented in 13 languages.
- Sekoia telemetry shows customer hosts communicating with Exvicy C2 servers, confirming the service is actively delivering malware.
- Sekoia tracked about 80 hosts serving the Exvicy admin panel by late August.
- Unlike ErrTraffic's EtherHiding technique, Exvicy hardcodes two C2 servers.
Coverage timelineoldest first · each row is one article
- · 5d agoNew Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
Infosecurity Magazine· 64
Sekoia says the Exvicy ClickFix malware service reuses ErrTraffic code and delivers payloads via WordPress.
- · 3d agoExvicy ClickFix Malware-as-a-Service Copies ErrTraffic to Hijack WordPress Sites
GBHackers· 45
New Exvicy MaaS uses compromised WordPress sites to deliver ClickFix lures mimicking Cloudflare Turnstile, assessed as a copycat of ErrTraffic.