Malware

New Exvicy malware-as-a-service framework copies rival’s code

According to Infosecurity Magazine, a new malware-as-a-service (MaaS) framework named Exvicy has emerged, built using code stolen from a competing service called ErrTraffic.

Exvicy operates as a ClickFix framework, distributing malware through compromised WordPress websites, according to Sekoia's Threat Detection & Research team. Threat actors advertise Exvicy on the Exploit.IN forum, with prices increasing from $1,200 to $2,000 per month. The service injects obfuscated JavaScript into vulnerable WordPress sites, presenting users with a fake Cloudflare Turnstile check. Victims are prompted to press Win+R, paste a command into the run dialog, and execute it, with instructions available in 13 languages. The framework reports each step back to the operator.

Security researchers at Sekoia assessed with high confidence that Exvicy reuses significant portions of ErrTraffic's code, including injected scripts and lure pages. The primary technical difference noted is ErrTraffic's use of the Polygon blockchain for C2 addresses, while Exvicy hardcodes two servers. It is believed Exvicy's developer likely obtained ErrTraffic's source code through a leak or by being a paying customer.

Source: Infosecurity Magazine

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

Related Terms

Adware

You can skip this ad in 5 seconds