← All hunts high TLP:CLEAR Part 2 of 2

ErrTraffic ClickFix PowerShell and Infostealer Activity

An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.

Based on research by Sekoia 2026-09-28 9 steps · 3 queries T1059.001 T1071 T1555

Brief

Why now?

Sekoia recently published research titled "Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework" (https://www.sekoia.com/blog/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework). The report details a high-conversion social engineering scheme where attackers trick users into pasting and running PowerShell commands to "fix" browser errors. Once executed, these commands download infostealers that harvest browser credentials. Because the framework uses blockchain-based domain resolution for its C2, infrastructure rotates quickly, making traditional static indicators less effective than behavioral hunting.

How the hunt flows

The hunt begins with a scoping phase using the hb_dns_activity surface. A query identifies hosts that have resolved known ErrTraffic C2 domains or blockchain-derived infrastructure within the last 14 days. This reduces the search space for more intensive behavioral queries. If the attacker uses new domains not in the provided list, the subsequent phases still run across the broader estate to find the activity.

In the second phase, the hunt executes two parallel queries to find behavioral evidence. The first query searches the hb_process_activity surface for PowerShell executions containing specific ClickFix download markers. The second query monitors the hb_file_activity surface for non-browser processes accessing browser credential files like "Login Data" or "Cookies". It baselines these accesses to exclude legitimate browser activity and focus on rare, suspicious reads.

Finally, an agent or analyst correlates these findings in the triage phase. By joining the DNS resolutions, the PowerShell command-line evidence, and the file access logs, the hunt establishes a complete infection chain. If a host shows evidence of both the lure and the harvesting, the playbook provides an action to isolate the host and revoke cloud sessions.

What this hunt cannot see

This hunt has two primary blind spots. First, it relies on endpoint telemetry. If an infection occurs on a host without an EDR agent, the hunt returns no results for that asset, potentially creating a false sense of security. Second, it cannot see the initial clipboard injection. We only see the activity once the user pastes and runs the command in PowerShell; the act of the website placing the command into the user's clipboard is invisible to these surfaces.

In this series

Steps

  1. DNS lookups to ErrTraffic C2

    Query · scoping

    Identify hosts resolving domains associated with the ErrTraffic framework to narrow the estate for behavioural queries.

    reads hb_dns_activitysql
    SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Hosts resolving known C2 domains. Silence indicates no direct resolution of the provided domains, which may occur if the attacker rotates blockchain-derived infrastructure.

  2. PowerShell execution with ClickFix lures

    Query · detection candidate

    Find PowerShell commands containing the specific download parameters and lure markers described in the report.

    reads hb_process_activitysql
    SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{powershell_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND LOWER(process_cmd_line) LIKE '%mode=download%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Process rows showing PowerShell used with ClickFix download markers. Silence means no such commands were executed within the window.

  3. Rare process access to browser data

    Query · baseline

    Identify non-browser processes reading sensitive browser credential files to establish harvesting behaviour.

    reads hb_file_activitysql
    SELECT device_hostname, process_name, file_name, file_path, COUNT(*) AS access_count, MIN(time) AS first_seen FROM hb_file_activity WHERE instr(',' || '{{credential_file_names}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND NOT (instr(',' || '{{legitimate_browsers}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, file_name, file_path HAVING access_count < 50

    What a hit looks like. A process that is not a browser reading browser databases. Silence suggests no suspicious harvesting occurred on those hosts.

  4. Triage ErrTraffic infection

    Agent triage

    Correlate the DNS resolution of C2 domains, the execution of lure-specific PowerShell commands, and the harvesting of browser data.

  5. Route on verdict

    Decision

    Route the workflow based on the agent's findings.

  6. Isolate host

    Response action

    Contain the infostealer infection immediately to prevent further exfiltration.

  7. Analyst forensic review

    Analyst task

    Verify the agent findings and identify the specific malware variant and C2 infrastructure.

  8. Hunt closure

    Analyst task

    Document the outcome and refine future hunt parameters.

Coverage

Scenario coverage

StageCoveredHow, or why not
User-Executed PowerShell Payload
T1059.001
Yes dns-to-errtraffic-c2, powershell-clickfix-execution
Infostealer Data Theft
T1555
Yes rare-credential-file-access
WordPress Account Compromise
T1190
Out of scope Relates to initial compromise of the distribution infrastructure, not the victim endpoint.
PHP Backdoor Deployment
T1190
Out of scope WordPress server persistence is handled in a separate hunt.
EtherHiding C2 Resolution
T1071
Out of scope Monitoring of blockchain smart contracts is out of scope for endpoint telemetry.
Social Engineering Lure Delivery
T1071
Out of scope Requires web server logs or browser instrumentation not present in the provided surfaces.
Malicious Clipboard Injection
T1115
Out of scope Endpoint surfaces cannot currently see the clipboard manipulation event.

Blind spots

  • Needs EDR agent coverage on all assets. A host without an agent will return zero rows, leading to a false sense of security regarding the total infection rate. It would answer whether an infection occurred on a host that does not report process or file activity.
  • Needs clipboard monitoring surface. The hunt relies on seeing the execution after the user pastes the command; the injection of the command itself into the clipboard is not visible on the provided surfaces. It would answer the exact contents of the clipboard lure before execution.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
c2_domainslist[domain]llc-image-ico.click, llc-image-ico.beer, exploit.inErrTraffic C2 domains and related infrastructure observed in campaigns.
credential_file_nameslist[string]login data, web data, cookiesTargeted browser credential files (case-insensitive match).
legitimate_browserslist[string]chrome.exe, msedge.exe, firefox.exe, brave.exeKnown browser processes allowed to access credential stores.
lookback_daysnumber14Days of history to examine.
powershell_binarieslist[string]powershell.exe, pwsh.exePowerShell executable names to monitor.
scope_hostslist[host]—List of hostnames from the scoping step to narrow the search.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: "This hunt correlates evidence across three surfaces\u2014DNS resolution\
  \ of suspicious domains, rare process access to browser credential stores, and specific\
  \ PowerShell command-line markers\u2014to identify a complete attack chain that\
  \ a single rule on any one surface would miss or over-alert on."
blind_spots:
- id: missing-endpoint-telemetry
  question: whether an infection occurred on a host that does not report process or
    file activity
  requires: EDR agent coverage on all assets
  risk: A host without an agent will return zero rows, leading to a false sense of
    security regarding the total infection rate.
- id: clipboard-visibility
  question: the exact contents of the clipboard lure before execution
  requires: clipboard monitoring surface
  risk: The hunt relies on seeing the execution after the user pastes the command;
    the injection of the command itself into the clipboard is not visible on the provided
    surfaces.
  stage: powershell-payload-execution
coverage:
- stage: powershell-payload-execution
  status: covered
  steps:
  - dns-to-errtraffic-c2
  - powershell-clickfix-execution
- stage: infostealer-credential-access
  status: covered
  steps:
  - rare-credential-file-access
- reason: Relates to initial compromise of the distribution infrastructure, not the
    victim endpoint.
  stage: wordpress-credential-compromise
  status: out_of_scope
- reason: WordPress server persistence is handled in a separate hunt.
  stage: backdoor-persistence
  status: out_of_scope
- reason: Monitoring of blockchain smart contracts is out of scope for endpoint telemetry.
  stage: blockchain-c2-resolution
  status: out_of_scope
- reason: Requires web server logs or browser instrumentation not present in the provided
    surfaces.
  stage: clickfix-lure-delivery
  status: out_of_scope
- reason: Endpoint surfaces cannot currently see the clipboard manipulation event.
  stage: clipboard-command-injection
  status: out_of_scope
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: promote-to-detection
  justification: ErrTraffic is a high-conversion MaaS framework. Detecting the endpoint
    results of its ClickFix lures is critical as its network infrastructure rotates
    frequently via blockchain resolvers.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An intruder has tricked a user into running a PowerShell command via a
  ClickFix lure, which downloads an infostealer to harvest credentials and connect
  to blockchain-resolved C2 domains.
labels:
- hunt
- attack.t1059.001
- attack.t1555
- attack.t1071
name: ErrTraffic ClickFix PowerShell and Infostealer Activity
parameters:
  c2_domains:
    default:
    - llc-image-ico.click
    - llc-image-ico.beer
    - exploit.in
    description: ErrTraffic C2 domains and related infrastructure observed in campaigns.
    from:
      kind: article
      observed: '2026-06-22'
      ref: sekoia-errtraffic
    type: list[domain]
  credential_file_names:
    default:
    - login data
    - web data
    - cookies
    description: Targeted browser credential files (case-insensitive match).
    from:
      kind: manual
      observed: '2026-06-22'
      ref: default
    type: list[string]
  legitimate_browsers:
    default:
    - chrome.exe
    - msedge.exe
    - firefox.exe
    - brave.exe
    description: Known browser processes allowed to access credential stores.
    from:
      kind: manual
      observed: '2026-06-22'
      ref: default
    type: list[string]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    from:
      kind: manual
      observed: '2026-06-22'
      ref: default
    type: number
  powershell_binaries:
    default:
    - powershell.exe
    - pwsh.exe
    description: PowerShell executable names to monitor.
    from:
      kind: manual
      observed: '2026-06-22'
      ref: default
    type: list[string]
  scope_hosts:
    default: []
    description: List of hostnames from the scoping step to narrow the search.
    from:
      kind: manual
      observed: '2026-06-22'
      ref: default
    type: list[host]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.sekoia.com/blog/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: Begin with Windows workstations and specifically examine DNS resolution
  of blockchain-derived domains. Use the results of the DNS query to narrow the scope
  for subsequent process and file queries.
references:
- name: "Sekoia \u2014 Unveiling ErrTraffic: inside a growing ClickFix malware distribution\
    \ framework"
  url: https://www.sekoia.com/blog/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework
related:
- hunt: wordpress-backdoor-persistence
  reason: This hunt focuses on the victim endpoints; investigating the server-side
    WordPress backdoors used to deliver ErrTraffic requires separate analysis of PHP
    activity.
  relation: out-of-scope-alternative
- hunt: errtraffic-infrastructure-delivery
  relation: follows
scenario:
  stages:
  - name: WordPress Account Compromise
    observables:
    - harvested credentials
    - WordPress sites
    - Exploit.IN forum
    slug: wordpress-credential-compromise
    tactic: initial-access
    techniques:
    - T1190
  - name: PHP Backdoor Deployment
    observables:
    - PHP backdoors
    - malicious WordPress plugin
    - ErrTraffic framework injection
    slug: backdoor-persistence
    tactic: persistence
    techniques:
    - T1190
  - name: EtherHiding C2 Resolution
    observables:
    - Polygon blockchain
    - '0x08207B087F61d7e95E441E15fd6d40BEfd6eD308'
    - Quicknode RPC
    - llc-image-ico.click
    - .beer
    - .cfd
    - .club
    - .click
    - .cyou
    - .lat
    - .sbs
    - .shop
    - .xyz
    slug: blockchain-c2-resolution
    tactic: command-and-control
    techniques:
    - T1071
  - name: Social Engineering Lure Delivery
    observables:
    - /cf.js
    - /api/css.js
    - /api/index.php
    - BSOD lure
    - reCAPTCHA lure
    - Cloudflare Turnstile lure
    slug: clickfix-lure-delivery
    tactic: execution
    techniques:
    - T1071
  - name: Malicious Clipboard Injection
    observables:
    - PowerShell command copied to clipboard
    slug: clipboard-command-injection
    tactic: collection
    techniques:
    - T1115
  - name: User-Executed PowerShell Payload
    observables:
    - powershell.exe
    - Net.WebClient download
    - mode=download
    slug: powershell-payload-execution
    tactic: execution
    techniques:
    - T1059.001
  - name: Infostealer Data Theft
    observables:
    - Vidar
    - Stealc
    - Remus
    - Salat
    slug: infostealer-credential-access
    tactic: credential-access
    techniques:
    - T1555
  summary: ErrTraffic is a Malware-as-a-Service (MaaS) framework that compromises
    WordPress sites to distribute infostealers using the 'ClickFix' social engineering
    technique. It uses the EtherHiding technique to resolve its command-and-control
    infrastructure via blockchain smart contracts and delivers malicious PowerShell
    commands that victims are tricked into executing manually.
series:
  index: 2
  slug: errtraffic-a-growing-clickfix-malware-distribution-framework
  title: 'ErrTraffic: A Growing ClickFix Malware Distribution Framework'
  total: 2
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
tlp: clear
type: investigation
---


# ErrTraffic ClickFix PowerShell and Infostealer Activity

This hunt identifies the endpoint manifestations of the ErrTraffic framework, a Malware-as-a-Service (MaaS) system that uses ClickFix social engineering. It targets the execution of PowerShell commands containing specific download parameters, correlates this with unauthorized access to browser credential stores by non-browser processes, and identifies DNS activity targeting blockchain-resolved C2 infrastructure.

## dns-to-errtraffic-c2
<!-- DNS lookups to ErrTraffic C2 -->
Identify hosts resolving domains associated with the ErrTraffic framework to narrow the estate for behavioural queries.

```sqlite target=endpoint role=scoping params=(c2_domains=c2_domains, lookback_days=lookback_days)
~~~yaml
expected: Hosts resolving known C2 domains. Silence indicates no direct resolution
  of the provided domains, which may occur if the attacker rotates blockchain-derived
  infrastructure.
reads:
- device_hostname
- query_hostname
- process_name
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')
```

## corroborate
<!-- Corroborate ClickFix execution and harvesting -->
parallel:
- → powershell-clickfix-execution
- → rare-credential-file-access
join: → triage-infection

## powershell-clickfix-execution
<!-- PowerShell execution with ClickFix lures -->
Find PowerShell commands containing the specific download parameters and lure markers described in the report.

```sqlite target=endpoint role=detection-candidate params=(powershell_binaries=powershell_binaries, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Process rows showing PowerShell used with ClickFix download markers. Silence
  means no such commands were executed within the window.
reads:
- device_hostname
- process_name
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{powershell_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND LOWER(process_cmd_line) LIKE '%mode=download%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```

## rare-credential-file-access
<!-- Rare process access to browser data -->
Identify non-browser processes reading sensitive browser credential files to establish harvesting behaviour.

```sqlite target=endpoint role=baseline params=(credential_file_names=credential_file_names, legitimate_browsers=legitimate_browsers, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: A process that is not a browser reading browser databases. Silence suggests
  no suspicious harvesting occurred on those hosts.
prevalence:
  by: device_hostname
  key:
  - process_name
  rare_below: 3
reads:
- device_hostname
- process_name
- file_name
- file_path
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, file_name, file_path, COUNT(*) AS access_count, MIN(time) AS first_seen FROM hb_file_activity WHERE instr(',' || '{{credential_file_names}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND NOT (instr(',' || '{{legitimate_browsers}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, file_name, file_path HAVING access_count < 50
```

## triage-infection
<!-- Triage ErrTraffic infection -->
```agent target=hunter
cite: required
context:
- dns-to-errtraffic-c2
- powershell-clickfix-execution
- rare-credential-file-access
max_iterations: 4
objective: Determine if a host was compromised by an ErrTraffic lure and if credential
  harvesting occurred.
success_criteria: A per-host verdict that identifies the malicious binary responsible
  for file access and its origin via PowerShell.
tools:
- endpoint
```

## route-on-verdict
<!-- Route on verdict -->
if~: "the triage-infection verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: missing-endpoint-telemetry)
else: → close-out

## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the endpoint from the network and revoke any active cloud sessions for the affected user.
```
→ analyst-review

## analyst-review
<!-- Analyst forensic review -->
```manual target=analyst
Review the cited rows from the triage step. Verify the binary that accessed the credential stores. Search for other persistence mechanisms installed by the payload.
```
→ close-out

## close-out
<!-- Hunt closure -->
```manual target=analyst
Record the results of the hunt. If new C2 domains were identified during forensic review, update the c2_domains parameter for future runs.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.