Malware · 9h ago

Exvicy’s WordPress Loader Has a Rival’s Blueprint

Sekoia says Exvicy, a ClickFix malware-as-a-service framework advertised on Exploit.IN, is actively being used against compromised WordPress sites. Its telemetry from multiple customer environments showed hosts talking to Exvicy command-and-control servers, which means this is not a concept demo or a dormant panel.

The lure starts with injected JavaScript on a hacked WordPress page that shows a fake Cloudflare check. The page then tells the victim to press Win+R, paste, and hit Enter, running a PowerShell command that was already copied to the clipboard; the operator can see each step and wait for the command to land on the endpoint.

Sekoia also found Exvicy’s injected script and lure pages are nearly identical to ErrTraffic’s, which points to reused code and a lower skill bar for operators. If WordPress is part of your delivery path, the exposed layer is no longer just the site itself but the browser-to-endpoint handoff the attacker can weaponize through it.

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-21

Editions

Related stories