Sekoia uncovers Exvicy, a new ClickFix MaaS built on ErrTraffic code
Sekoia's threat research team detailed Exvicy, a ClickFix malware-as-a-service framework that injects obfuscated JavaScript into compromised WordPress sites and lures victims into running PowerShell via Win+R. The Russian-speaking operator has sold it on Exploit.IN since May 26, raising the price from $1,200 to $2,000 a month, with roughly 80 panel-hosting servers found by late August.
- Exvicy has been advertised on Exploit.IN since May 26, rising from $1,200 to $2,000 per month
- Lure pages give instructions in 13 languages and report each victim step to the operator
- Sekoia traced the panel from an advert screenshot and counted about 80 hosts by late August
- Unlike ErrTraffic's Polygon-based C2, Exvicy hardcodes two servers
Read next
Security