Threat Management, Threat Intelligence

Automated ClickFix intrusions facilitated by novel ErrTraffic tool

BleepingComputer reports that the newly emergent cybercrime platform ErrTraffic could trigger bogus glitches on breached websites to facilitate automated ClickFix attacks.

Threat actors who have taken over websites permitting victim traffic or infected websites with malicious code could use ErrTraffic, a self-hosted traffic distribution system offered for $800 by developer LenAI, to show visual glitches on websites depending on visitors' geolocation and operating system fingerprinting conditions, according to Hudson Rock analysts. Visitors are then shown a pop-up luring them into downloading a browser update and system font, or pasting text into the command prompt, which then installs the Vidar and Lumma information-stealing payloads on Windows, AMOS malware on macOS, and Cerberus trojan on Android, as well as unnamed Linux backdoors.

Information stolen by the payloads was then used to enable further compromise with ErrTraffic, said researchers, who noted the platform's exclusion for Commonwealth of Independent States nations.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds