BleepingComputer reports that the newly emergent cybercrime platform ErrTraffic could trigger bogus glitches on breached websites to facilitate automated ClickFix attacks.
Threat actors who have taken over websites permitting victim traffic or infected websites with malicious code could use ErrTraffic, a self-hosted traffic distribution system offered for $800 by developer LenAI, to show visual glitches on websites depending on visitors' geolocation and operating system fingerprinting conditions, according to Hudson Rock analysts. Visitors are then shown a pop-up luring them into downloading a browser update and system font, or pasting text into the command prompt, which then installs the Vidar and Lumma information-stealing payloads on Windows, AMOS malware on macOS, and Cerberus trojan on Android, as well as unnamed Linux backdoors.
Information stolen by the payloads was then used to enable further compromise with ErrTraffic, said researchers, who noted the platform's exclusion for Commonwealth of Independent States nations.
Threat actors who have taken over websites permitting victim traffic or infected websites with malicious code could use ErrTraffic, a self-hosted traffic distribution system offered for $800 by developer LenAI, to show visual glitches on websites depending on visitors' geolocation and operating system fingerprinting conditions, according to Hudson Rock analysts. Visitors are then shown a pop-up luring them into downloading a browser update and system font, or pasting text into the command prompt, which then installs the Vidar and Lumma information-stealing payloads on Windows, AMOS malware on macOS, and Cerberus trojan on Android, as well as unnamed Linux backdoors.
Information stolen by the payloads was then used to enable further compromise with ErrTraffic, said researchers, who noted the platform's exclusion for Commonwealth of Independent States nations.
