ErrTraffic ClickFix Campaigns Use Cruciferra Loader to Disable Security Tools

· Original article ↗

Summary

eSentire analyzed late-July 2026 ErrTraffic ClickFix campaigns that used fake CAPTCHA and BSOD prompts to run PowerShell and deploy Cruciferra, which can abuse a signed vulnerable driver to terminate security processes before loading the Remus stealer.

Key points

  • Compromised WordPress sites served obfuscated ErrTraffic scripts that resolved command-and-control addresses through blockchain smart contracts and loaded ClickFix lures.
  • The lures impersonated Google reCAPTCHA, Cloudflare Turnstile, or a system error, tricking victims into copying and executing malicious PowerShell commands.
  • Cruciferra was delivered through DLL sideloading and used process hollowing to inject the Remus information stealer into a legitimate Windows process.
  • When configured for EDR killing, Cruciferra loads the signed vulnerable driver DCRCVDrv.sys and uses its kernel-level IOCTL to terminate targeted processes, including 145 AV/EDR-related processes.
  • eSentire identifies ErrTraffic and Cruciferra as separate malware-as-a-service offerings and describes their operator panels and delivery capabilities.
  • eSentire says its analysts isolated the affected host; it recommends blocking the vulnerable driver and reports ongoing monitoring and detection-content development.

Article Details

Attack Vectors
  • Victims visited compromised WordPress sites containing an obfuscated ErrTraffic JavaScript inject. The inject resolved a C2 address through a Polygon smart contract and loaded a ClickFix lure from that C2.
  • The ClickFix lure impersonated Google reCAPTCHA, Cloudflare Turnstile, or a system error and instructed victims to paste and execute a malicious PowerShell command.
  • Subsequent PowerShell stages used a legitimate Microsoft-signed binary to side-load a Cruciferra DLL. Cruciferra used process hollowing to inject the Remus information stealer into ServiceModelReg.exe.
  • When configured to use its UAC-bypass and AV/EDR-killer features, Cruciferra attempted elevation through the COM Elevation Moniker, loaded the vulnerable signed driver DCRCVDrv.sys, and used it to terminate targeted security processes from the kernel.
Defensive Notes
  • eSentire isolated an affected host and assisted its customer with remediation.
  • The Threat Response Unit recommends blocking DCRCVDrv.sys using the supplied driver hashes in an EDR/AV console.
  • The Threat Response Unit recommends phishing and security-awareness training covering scenarios such as ClickFix lures, alongside endpoint protection and managed detection and response.

Indicators of compromise

TypeIndicatorContext
DOMAINanalysis-id-fmd[.]infoErrTraffic C2 domain listed in the indicators table.
DOMAINanalysis-id-lfg[.]infoErrTraffic C2 domain listed in the indicators table.
DOMAINkarmactive[.]comCompromised WordPress site carrying an ErrTraffic inject.
DOMAINmakeverizyjar[.]infoErrTraffic C2 domain.
DOMAINtzpx[.]coursesRemus C2 domain.
DOMAINzelpx[.]gardenRemus C2 domain listed in the indicators table.
IPV4178[.]16[.]52[.]101Suspicious IPv4 address listed in the article's indicators-of-compromise table.
MD5567c158ee0858f8e941d4ab7a6c18dbcHash supplied for blocking the vulnerable DCRCVDrv.sys driver.
SHA147d922b0fd5d704025d14ef98ded46e74830a423Hash supplied for blocking the vulnerable DCRCVDrv.sys driver.
SHA2560ae0a7f118b80e4655b8b86bb421c151a8f17930e76e714b2fa199409f3af9ceHash of the Cruciferra DLL, mscoree.dll.
SHA256611b3ba687b7f46319a19609605ddfe5225e6d85277d8e923eea3fdb6f7b5b61Hash of the vulnerable Alinubx.sys driver listed in the indicators table.
SHA25687e8d39db624f37d3e77aedf487a2dfd197f71a4730ea74f4e7a4341deaec2ffHash of the vulnerable DCRCVDrv.sys driver abused to terminate AV/EDR processes.

MITRE ATT&CK

People

Threat Actors

Malware

Vendors

Products

AvastAvastAVGAVGAviraavcenter.exe, avguard.exe, avira.servicehost.exe, aviramain.exe, avscan.exe, avshadow.exe, sched.exeBitdefenderBitdefenderCarbon BlackCarbon BlackClamAVClamAVCrowdStrike FalconCrowdStrike FalconCybereasonCybereasonCylanceCylance (BlackBerry)Dr.WebDr.WebElastic Endpoint SecurityElastic Endpoint SecurityeSentire MDR for EndpointTRU is closely monitoring campaigns involving ErrTraffic, Cruciferra, and BYOVDs, and developing up-to-date detection content for eSentire MDR for Endpoint, eSentire MDR for Log, and eSentire MDR for Network.eSentire MDR for LogTRU is closely monitoring campaigns involving ErrTraffic, Cruciferra, and BYOVDs, and developing up-to-date detection content for eSentire MDR for Endpoint, eSentire MDR for Log, and eSentire MDR for Network.eSentire MDR for NetworkTRU is closely monitoring campaigns involving ErrTraffic, Cruciferra, and BYOVDs, and developing up-to-date detection content for eSentire MDR for Endpoint, eSentire MDR for Log, and eSentire MDR for Network.ESETESETF-ProtF-ProtF-SecureF-SecureFortinet FortiEDRFortinet FortiEDRG DataG DataHitmanPro.AlertHitmanPro.Alert (Sophos)HuorongHuorongK7 ComputingK7 ComputingKasperskyKasperskyMalwarebytesMalwarebytesMcAfeeMcAfeeMicrosoft DefenderMicrosoft DefenderMicrosoft Defender for EndpointMicrosoft Defender for EndpointMicrosoft Windowsa malicious PowerShell command to the victim's clipboard and instructs them to open it in PowerShell via Windows Key + X -> I, then paste and execute it.Palo Alto Cortex XDRPalo Alto Cortex XDRPanda SecurityPanda SecurityQihoo 360Qihoo 360SentinelOneSentinelOneSophosHitmanPro.Alert (Sophos)Trend MicroTrend MicroVIPREVIPREWebrootWebrootWordPressVictims land on compromised WordPress sites injected with an obfuscated ErrTraffic-generated JavaScript loader. The loader resolves its C2 domain by querying a Polygon smart contract, then sends a request to the C2 to

Tools

Related Articles