ErrTraffic: ClickFix framework sold as a service
Researchers at Sekoia have published an analysis of ErrTraffic, a JavaScript framework used to deliver ClickFix lures to visitors through compromised websites. The framework is marketed and sold as a malware-as-a-service product, and uses Polygon blockchain smart contracts to resolve command-and-control domains. Components include a traffic distribution system that serves different malware families, among them Vidar and Remus, based on parameters such as referrer, operating system and geolocation. Sekoia also details observed activity clusters and the progression from initial reconnaissance and site compromise through to deployment and operation of the framework and its supporting backdoors.
What this means for your organisation
ClickFix persuades the user to paste and run a command themselves, usually under the pretext that something needs fixing in the browser. That bypasses much of your technical protection, because the action comes from a logged-in user on an approved machine. Resolving C2 through a blockchain makes the infrastructure hard to take down, and selling the framework on means multiple actors can run campaigns in parallel. For most organisations this is primarily a question of what employees do when a web page asks them for something unusual.
Berigo recommends
- Give staff one clear rule: a web page should never ask you to paste a command into Windows or a terminal.
- Restrict the ability to run PowerShell and scripts from the Run dialog for users who do not need it.
- Monitor for command execution initiated immediately after browser activity, and make it a standing detection rule.
- Include ClickFix as a scenario in your incident response exercise so the first line recognises the pattern.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch