A new cybercrime tool called ErrTraffic enables malicious actors to automate ClickFix, creating “fake malfunctions” on compromised websites, with the aim of tricking users into downloading malicious payloads or executing dangerous instructions.
See also: Storm-0249: Escalating ransomware attacks with ClickFix and DLL Sideloading

The platform promises success rates of up to 60% and can identify the target system in order to send compatible payloads.
ClickFix dangerous commands on their computers under plausible pretexts, such as resolving technical issues or verifying their identity. The method has gained popularity since 2024 and especially this year, as both cybercriminals and state-sponsored actors have exploited it due to its ability to bypass standard security measures. ErrTraffic is a new cybercrime platform that was first promoted earlier this month on Russian-language hacker forums by an individual using the pseudonym LenAI.
It operates as a self-hosted traffic distribution system (TDS) used to deploy ClickFix traps and is sold for a one-time fee of $800. Hudson Rock researchers who studied the platform report that it has a user-friendly dashboard, with many customization options and access to real-time campaign data.
To use it, the attacker must already control a website that receives traffic from victims or have injected malicious code into a legitimate but compromised website and then embed ErrTraffic by adding a single line of HTML.
See also: ClickFix: Fake Windows update to distribute malware

The website behavior remains unchanged for regular visitors who do not meet the targeting criteria. However, when the geolocation and operating system fingerprint conditions are met, the page's DOM is modified to display a visual "error.".
These problems may include garbled or illegible text, replacement of fonts with symbols, fake Chrome updates, or messages about supposedly missing system fonts.
This makes the page appear “broken” and creates the appropriate background to offer the victim a supposed “solution”, such as installing a browser update, downloading a system font or pasting a command into the command line. If the victim follows the instructions, a PowerShell code is copied to the clipboard via JavaScript. Executing the command leads to the download of a malicious payload. Hudson Rock clarifies that the payloads include the info-stealers Lumma and Vidar for Windows, the Cerberus for Android, AMOS (Atomic Stealer) for macOS and unnamed backdoors for Linux.
ErrTraffic clients can define a different payload for each targeted architecture and specify which countries qualify for infection. However, there is a built-in exclusion for CIS (Commonwealth of Independent States) countries, which may indicate the origin of ErrTraffic's creator.
See also: EVALUSION: New ClickFix campaign distributes Amatera Stealer and NetSupport RAT

Hudson Rock, which tracks the entire lifecycle of credential theft, reports that in most cases the data collected is sold on darknet marketplaces or leveraged to hack more websites and re-inject the ErrTraffic script.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
