Malware · 9h ago
Sekoia says Exvicy, a ClickFix malware-as-a-service framework advertised on Exploit.IN, is actively being used against compromised WordPress sites. Its telemetry from multiple customer environments showed hosts talking to Exvicy command-and-control servers, which means this is not a concept demo or a dormant panel.
The lure starts with injected JavaScript on a hacked WordPress page that shows a fake Cloudflare check. The page then tells the victim to press Win+R, paste, and hit Enter, running a PowerShell command that was already copied to the clipboard; the operator can see each step and wait for the command to land on the endpoint.
Sekoia also found Exvicy’s injected script and lure pages are nearly identical to ErrTraffic’s, which points to reused code and a lower skill bar for operators. If WordPress is part of your delivery path, the exposed layer is no longer just the site itself but the browser-to-endpoint handoff the attacker can weaponize through it.
1 source covering this story
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
Sekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTraffic
Part of the PlainSec briefing for 2026-09-21