ErrTraffic ClickFix Campaigns Use Cruciferra Loader to Disable Security Tools

Summary
eSentire analyzed late-July 2026 ErrTraffic ClickFix campaigns that used fake CAPTCHA and BSOD prompts to run PowerShell and deploy Cruciferra, which can abuse a signed vulnerable driver to terminate security processes before loading the Remus stealer.
Key points
- Compromised WordPress sites served obfuscated ErrTraffic scripts that resolved command-and-control addresses through blockchain smart contracts and loaded ClickFix lures.
- The lures impersonated Google reCAPTCHA, Cloudflare Turnstile, or a system error, tricking victims into copying and executing malicious PowerShell commands.
- Cruciferra was delivered through DLL sideloading and used process hollowing to inject the Remus information stealer into a legitimate Windows process.
- When configured for EDR killing, Cruciferra loads the signed vulnerable driver DCRCVDrv.sys and uses its kernel-level IOCTL to terminate targeted processes, including 145 AV/EDR-related processes.
- eSentire identifies ErrTraffic and Cruciferra as separate malware-as-a-service offerings and describes their operator panels and delivery capabilities.
- eSentire says its analysts isolated the affected host; it recommends blocking the vulnerable driver and reports ongoing monitoring and detection-content development.
Article Details
- Attack Vectors
- Victims visited compromised WordPress sites containing an obfuscated ErrTraffic JavaScript inject. The inject resolved a C2 address through a Polygon smart contract and loaded a ClickFix lure from that C2.
- The ClickFix lure impersonated Google reCAPTCHA, Cloudflare Turnstile, or a system error and instructed victims to paste and execute a malicious PowerShell command.
- Subsequent PowerShell stages used a legitimate Microsoft-signed binary to side-load a Cruciferra DLL. Cruciferra used process hollowing to inject the Remus information stealer into ServiceModelReg.exe.
- When configured to use its UAC-bypass and AV/EDR-killer features, Cruciferra attempted elevation through the COM Elevation Moniker, loaded the vulnerable signed driver DCRCVDrv.sys, and used it to terminate targeted security processes from the kernel.
- Defensive Notes
- eSentire isolated an affected host and assisted its customer with remediation.
- The Threat Response Unit recommends blocking DCRCVDrv.sys using the supplied driver hashes in an EDR/AV console.
- The Threat Response Unit recommends phishing and security-awareness training covering scenarios such as ClickFix lures, alongside endpoint protection and managed detection and response.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | analysis-id-fmd[.]info | ErrTraffic C2 domain listed in the indicators table. |
| DOMAIN | analysis-id-lfg[.]info | ErrTraffic C2 domain listed in the indicators table. |
| DOMAIN | karmactive[.]com | Compromised WordPress site carrying an ErrTraffic inject. |
| DOMAIN | makeverizyjar[.]info | ErrTraffic C2 domain. |
| DOMAIN | tzpx[.]courses | Remus C2 domain. |
| DOMAIN | zelpx[.]garden | Remus C2 domain listed in the indicators table. |
| IPV4 | 178[.]16[.]52[.]101 | Suspicious IPv4 address listed in the article's indicators-of-compromise table. |
| MD5 | 567c158ee0858f8e941d4ab7a6c18dbc | Hash supplied for blocking the vulnerable DCRCVDrv.sys driver. |
| SHA1 | 47d922b0fd5d704025d14ef98ded46e74830a423 | Hash supplied for blocking the vulnerable DCRCVDrv.sys driver. |
| SHA256 | 0ae0a7f118b80e4655b8b86bb421c151a8f17930e76e714b2fa199409f3af9ce | Hash of the Cruciferra DLL, mscoree.dll. |
| SHA256 | 611b3ba687b7f46319a19609605ddfe5225e6d85277d8e923eea3fdb6f7b5b61 | Hash of the vulnerable Alinubx.sys driver listed in the indicators table. |
| SHA256 | 87e8d39db624f37d3e77aedf487a2dfd197f71a4730ea74f4e7a4341deaec2ff | Hash of the vulnerable DCRCVDrv.sys driver abused to terminate AV/EDR processes. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe ErrTraffic inject was base64-encoded and XOR-encrypted; Cruciferra also stored encrypted strings.T1055.012 · Process HollowingCruciferra used process hollowing to inject Remus into the address space of ServiceModelReg.exe.T1059.001 · PowerShellClickFix lures instructed victims to execute a malicious PowerShell command; additional PowerShell stages followed.T1102.001 · Dead Drop ResolverThe ErrTraffic inject queried a Polygon smart contract to resolve a periodically rotated C2 domain.T1189 · Drive-by CompromiseVictims encountered the ErrTraffic JavaScript inject while visiting compromised WordPress sites.T1548.002 · Bypass User Account ControlCruciferra attempted to elevate privileges using the COM Elevation Moniker when its UAC-bypass feature was enabled.T1562.001 · Disable or Modify ToolsCruciferra used the vulnerable DCRCVDrv.sys driver to terminate targeted AV/EDR processes from the kernel.T1574.001 · DLLA legitimate Microsoft-signed binary side-loaded the Cruciferra DLL named mscoree.dll.
People
Threat Actors
Malware
COCONUTPUROSANGUE stub is a side-loaded DLL priced at $1200 per month with EDR/AV killing capabilities, whereas COCONUT is a self-contained EXE with a Windows Defender exclusion capability and is priced at $650 per month.CruciferraResponse Unit (TRU) identified several ErrTraffic-generated ClickFix campaigns attempting to deliver Cruciferra - a malware loader marketed on underground forums that boasts EDR-killing capabilities. TRU foundPUROSANGUETRU assesses with high confidence that this payload was generated by an operator using the "PUROSANGUE" package, described later in this blog.Remus[T1574.001] the Cruciferra DLL (mscoree.dll), which uses process hollowing [T1055.012] to inject the Remus information stealer into the address space of the legitimate, Microsoft-signed binary ServiceModelReg.exe.
Vendors
eSentireIn late July 2026, eSentire's Threat Response Unit (TRU) identified several ErrTraffic-generated ClickFix campaigns attempting to deliver Cruciferra - a malware loader marketed on underground forums that boastsMicrosoftdiscovered several additional PowerShell stages following the initial ClickFix command - a legitimate, Microsoft signed binary was used to side-load [T1574.001] the Cruciferra DLL (mscoree.dll), which uses processMocoMsysfulfill this behavior. The driver, also known as, "DCRCVDrv.sys", is signed by South Korean IT company MocoMsys and exposes an IOCTL that allows user-mode applications to terminate processes directly from the kernel.
Products
AvastAvastAVGAVGAviraavcenter.exe, avguard.exe, avira.servicehost.exe, aviramain.exe, avscan.exe, avshadow.exe, sched.exeBitdefenderBitdefenderCarbon BlackCarbon BlackClamAVClamAVCrowdStrike FalconCrowdStrike FalconCybereasonCybereasonCylanceCylance (BlackBerry)Dr.WebDr.WebElastic Endpoint SecurityElastic Endpoint SecurityeSentire MDR for EndpointTRU is closely monitoring campaigns involving ErrTraffic, Cruciferra, and BYOVDs, and developing up-to-date detection content for eSentire MDR for Endpoint, eSentire MDR for Log, and eSentire MDR for Network.eSentire MDR for LogTRU is closely monitoring campaigns involving ErrTraffic, Cruciferra, and BYOVDs, and developing up-to-date detection content for eSentire MDR for Endpoint, eSentire MDR for Log, and eSentire MDR for Network.eSentire MDR for NetworkTRU is closely monitoring campaigns involving ErrTraffic, Cruciferra, and BYOVDs, and developing up-to-date detection content for eSentire MDR for Endpoint, eSentire MDR for Log, and eSentire MDR for Network.ESETESETF-ProtF-ProtF-SecureF-SecureFortinet FortiEDRFortinet FortiEDRG DataG DataHitmanPro.AlertHitmanPro.Alert (Sophos)HuorongHuorongK7 ComputingK7 ComputingKasperskyKasperskyMalwarebytesMalwarebytesMcAfeeMcAfeeMicrosoft DefenderMicrosoft DefenderMicrosoft Defender for EndpointMicrosoft Defender for EndpointMicrosoft Windowsa malicious PowerShell command to the victim's clipboard and instructs them to open it in PowerShell via Windows Key + X -> I, then paste and execute it.Palo Alto Cortex XDRPalo Alto Cortex XDRPanda SecurityPanda SecurityQihoo 360Qihoo 360SentinelOneSentinelOneSophosHitmanPro.Alert (Sophos)Trend MicroTrend MicroVIPREVIPREWebrootWebrootWordPressVictims land on compromised WordPress sites injected with an obfuscated ErrTraffic-generated JavaScript loader. The loader resolves its C2 domain by querying a Polygon smart contract, then sends a request to the C2 to
Tools
Binary NinjaAt the time of our analysis, there was no plugin available for Binary Ninja to extract metadata from NativeAOT-based samples. In response, we ported @vinopaljiri's NativeAOT plugin from IDA Pro to Binary Ninja. ForErrTrafficIn late July 2026, eSentire's Threat Response Unit (TRU) identified several ErrTraffic-generated ClickFix campaigns attempting to deliver Cruciferra - a malware loader marketed on underground forums that boastsGhidrawe opened pull requests to enable support for .NET 7.0 compiled plugins in @washi_dev's repository for Ghidra and @vinopaljiri's repository for IDA Pro. After making use of the plugin, all of the base64-encoded +IDA Prometadata from NativeAOT-based samples. In response, we ported @vinopaljiri's NativeAOT plugin from IDA Pro to Binary Ninja. For usage and installation instructions, see our Github repository available here.