ErrTraffic ClickFix PowerShell and Infostealer Activity
An intruder has tricked a user into running a PowerShell command via a ClickFix lure, which downloads an infostealer to harvest credentials and connect to blockchain-resolved C2 domains.
Based on research by Sekoia 2026-09-28 9 steps · 3 queries T1059.001 T1071 T1555
Brief
Why now?
Sekoia recently published research titled "Unveiling ErrTraffic: inside a growing ClickFix malware distribution framework" (https://www.sekoia.com/blog/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework). The report details a high-conversion social engineering scheme where attackers trick users into pasting and running PowerShell commands to "fix" browser errors. Once executed, these commands download infostealers that harvest browser credentials. Because the framework uses blockchain-based domain resolution for its C2, infrastructure rotates quickly, making traditional static indicators less effective than behavioral hunting.
How the hunt flows
The hunt begins with a scoping phase using the hb_dns_activity surface. A query identifies hosts that have resolved known ErrTraffic C2 domains or blockchain-derived infrastructure within the last 14 days. This reduces the search space for more intensive behavioral queries. If the attacker uses new domains not in the provided list, the subsequent phases still run across the broader estate to find the activity.
In the second phase, the hunt executes two parallel queries to find behavioral evidence. The first query searches the hb_process_activity surface for PowerShell executions containing specific ClickFix download markers. The second query monitors the hb_file_activity surface for non-browser processes accessing browser credential files like "Login Data" or "Cookies". It baselines these accesses to exclude legitimate browser activity and focus on rare, suspicious reads.
Finally, an agent or analyst correlates these findings in the triage phase. By joining the DNS resolutions, the PowerShell command-line evidence, and the file access logs, the hunt establishes a complete infection chain. If a host shows evidence of both the lure and the harvesting, the playbook provides an action to isolate the host and revoke cloud sessions.
What this hunt cannot see
This hunt has two primary blind spots. First, it relies on endpoint telemetry. If an infection occurs on a host without an EDR agent, the hunt returns no results for that asset, potentially creating a false sense of security. Second, it cannot see the initial clipboard injection. We only see the activity once the user pastes and runs the command in PowerShell; the act of the website placing the command into the user's clipboard is invisible to these surfaces.
In this series
Steps
-
DNS lookups to ErrTraffic C2
Query · scopingIdentify hosts resolving domains associated with the ErrTraffic framework to narrow the estate for behavioural queries.
reads hb_dns_activitysqlSELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Hosts resolving known C2 domains. Silence indicates no direct resolution of the provided domains, which may occur if the attacker rotates blockchain-derived infrastructure.
-
PowerShell execution with ClickFix lures
Query · detection candidateFind PowerShell commands containing the specific download parameters and lure markers described in the report.
reads hb_process_activitysqlSELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{powershell_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND LOWER(process_cmd_line) LIKE '%mode=download%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')What a hit looks like. Process rows showing PowerShell used with ClickFix download markers. Silence means no such commands were executed within the window.
-
Rare process access to browser data
Query · baselineIdentify non-browser processes reading sensitive browser credential files to establish harvesting behaviour.
reads hb_file_activitysqlSELECT device_hostname, process_name, file_name, file_path, COUNT(*) AS access_count, MIN(time) AS first_seen FROM hb_file_activity WHERE instr(',' || '{{credential_file_names}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND NOT (instr(',' || '{{legitimate_browsers}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, file_name, file_path HAVING access_count < 50What a hit looks like. A process that is not a browser reading browser databases. Silence suggests no suspicious harvesting occurred on those hosts.
-
Triage ErrTraffic infection
Agent triageCorrelate the DNS resolution of C2 domains, the execution of lure-specific PowerShell commands, and the harvesting of browser data.
-
Route on verdict
DecisionRoute the workflow based on the agent's findings.
-
Isolate host
Response actionContain the infostealer infection immediately to prevent further exfiltration.
-
Analyst forensic review
Analyst taskVerify the agent findings and identify the specific malware variant and C2 infrastructure.
-
Hunt closure
Analyst taskDocument the outcome and refine future hunt parameters.
Coverage
Scenario coverage
| Stage | Covered | How, or why not |
|---|---|---|
| User-Executed PowerShell Payload T1059.001 |
Yes | dns-to-errtraffic-c2, powershell-clickfix-execution |
| Infostealer Data Theft T1555 |
Yes | rare-credential-file-access |
| WordPress Account Compromise T1190 |
Out of scope | Relates to initial compromise of the distribution infrastructure, not the victim endpoint. |
| PHP Backdoor Deployment T1190 |
Out of scope | WordPress server persistence is handled in a separate hunt. |
| EtherHiding C2 Resolution T1071 |
Out of scope | Monitoring of blockchain smart contracts is out of scope for endpoint telemetry. |
| Social Engineering Lure Delivery T1071 |
Out of scope | Requires web server logs or browser instrumentation not present in the provided surfaces. |
| Malicious Clipboard Injection T1115 |
Out of scope | Endpoint surfaces cannot currently see the clipboard manipulation event. |
Blind spots
- Needs EDR agent coverage on all assets. A host without an agent will return zero rows, leading to a false sense of security regarding the total infection rate. It would answer whether an infection occurred on a host that does not report process or file activity.
- Needs clipboard monitoring surface. The hunt relies on seeing the execution after the user pastes the command; the injection of the command itself into the clipboard is not visible on the provided surfaces. It would answer the exact contents of the clipboard lure before execution.
Parameters & data
Parameters
| Parameter | Type | Default | What it is |
|---|---|---|---|
c2_domains | list[domain] | llc-image-ico.click, llc-image-ico.beer, exploit.in | ErrTraffic C2 domains and related infrastructure observed in campaigns. |
credential_file_names | list[string] | login data, web data, cookies | Targeted browser credential files (case-insensitive match). |
legitimate_browsers | list[string] | chrome.exe, msedge.exe, firefox.exe, brave.exe | Known browser processes allowed to access credential stores. |
lookback_days | number | 14 | Days of history to examine. |
powershell_binaries | list[string] | powershell.exe, pwsh.exe | PowerShell executable names to monitor. |
scope_hosts | list[host] | — | List of hostnames from the scoping step to narrow the search. |
Telemetry
| Source | Category | Telemetry |
|---|---|---|
| Endpoint telemetry (hb_ surfaces) | endpoint | endpoint |
Source
---
analysis: "This hunt correlates evidence across three surfaces\u2014DNS resolution\
\ of suspicious domains, rare process access to browser credential stores, and specific\
\ PowerShell command-line markers\u2014to identify a complete attack chain that\
\ a single rule on any one surface would miss or over-alert on."
blind_spots:
- id: missing-endpoint-telemetry
question: whether an infection occurred on a host that does not report process or
file activity
requires: EDR agent coverage on all assets
risk: A host without an agent will return zero rows, leading to a false sense of
security regarding the total infection rate.
- id: clipboard-visibility
question: the exact contents of the clipboard lure before execution
requires: clipboard monitoring surface
risk: The hunt relies on seeing the execution after the user pastes the command;
the injection of the command itself into the clipboard is not visible on the provided
surfaces.
stage: powershell-payload-execution
coverage:
- stage: powershell-payload-execution
status: covered
steps:
- dns-to-errtraffic-c2
- powershell-clickfix-execution
- stage: infostealer-credential-access
status: covered
steps:
- rare-credential-file-access
- reason: Relates to initial compromise of the distribution infrastructure, not the
victim endpoint.
stage: wordpress-credential-compromise
status: out_of_scope
- reason: WordPress server persistence is handled in a separate hunt.
stage: backdoor-persistence
status: out_of_scope
- reason: Monitoring of blockchain smart contracts is out of scope for endpoint telemetry.
stage: blockchain-c2-resolution
status: out_of_scope
- reason: Requires web server logs or browser instrumentation not present in the provided
surfaces.
stage: clickfix-lure-delivery
status: out_of_scope
- reason: Endpoint surfaces cannot currently see the clipboard manipulation event.
stage: clipboard-command-injection
status: out_of_scope
guardrails:
claims: no_unsupported
evidence: citation_required
missing_data: not_benign
telemetry: untrusted
hunt:
applicability: campaign-specific
handoff: promote-to-detection
justification: ErrTraffic is a high-conversion MaaS framework. Detecting the endpoint
results of its ClickFix lures is critical as its network infrastructure rotates
frequently via blockchain resolvers.
methodology: model-assisted
trigger: intel-report
hypothesis: An intruder has tricked a user into running a PowerShell command via a
ClickFix lure, which downloads an infostealer to harvest credentials and connect
to blockchain-resolved C2 domains.
labels:
- hunt
- attack.t1059.001
- attack.t1555
- attack.t1071
name: ErrTraffic ClickFix PowerShell and Infostealer Activity
parameters:
c2_domains:
default:
- llc-image-ico.click
- llc-image-ico.beer
- exploit.in
description: ErrTraffic C2 domains and related infrastructure observed in campaigns.
from:
kind: article
observed: '2026-06-22'
ref: sekoia-errtraffic
type: list[domain]
credential_file_names:
default:
- login data
- web data
- cookies
description: Targeted browser credential files (case-insensitive match).
from:
kind: manual
observed: '2026-06-22'
ref: default
type: list[string]
legitimate_browsers:
default:
- chrome.exe
- msedge.exe
- firefox.exe
- brave.exe
description: Known browser processes allowed to access credential stores.
from:
kind: manual
observed: '2026-06-22'
ref: default
type: list[string]
lookback_days:
default: '14'
description: Days of history to examine.
from:
kind: manual
observed: '2026-06-22'
ref: default
type: number
powershell_binaries:
default:
- powershell.exe
- pwsh.exe
description: PowerShell executable names to monitor.
from:
kind: manual
observed: '2026-06-22'
ref: default
type: list[string]
scope_hosts:
default: []
description: List of hostnames from the scoping step to narrow the search.
from:
kind: manual
observed: '2026-06-22'
ref: default
type: list[host]
provenance:
authors:
- name: Huntbase hunt generation
org: huntbase.io
generated:
by: huntbase-hunt-generation
from: https://www.sekoia.com/blog/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework
gates:
- dry-run
- lint
- critic
model: hb_google/gemini-3-flash-preview
rationale: Begin with Windows workstations and specifically examine DNS resolution
of blockchain-derived domains. Use the results of the DNS query to narrow the scope
for subsequent process and file queries.
references:
- name: "Sekoia \u2014 Unveiling ErrTraffic: inside a growing ClickFix malware distribution\
\ framework"
url: https://www.sekoia.com/blog/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework
related:
- hunt: wordpress-backdoor-persistence
reason: This hunt focuses on the victim endpoints; investigating the server-side
WordPress backdoors used to deliver ErrTraffic requires separate analysis of PHP
activity.
relation: out-of-scope-alternative
- hunt: errtraffic-infrastructure-delivery
relation: follows
scenario:
stages:
- name: WordPress Account Compromise
observables:
- harvested credentials
- WordPress sites
- Exploit.IN forum
slug: wordpress-credential-compromise
tactic: initial-access
techniques:
- T1190
- name: PHP Backdoor Deployment
observables:
- PHP backdoors
- malicious WordPress plugin
- ErrTraffic framework injection
slug: backdoor-persistence
tactic: persistence
techniques:
- T1190
- name: EtherHiding C2 Resolution
observables:
- Polygon blockchain
- '0x08207B087F61d7e95E441E15fd6d40BEfd6eD308'
- Quicknode RPC
- llc-image-ico.click
- .beer
- .cfd
- .club
- .click
- .cyou
- .lat
- .sbs
- .shop
- .xyz
slug: blockchain-c2-resolution
tactic: command-and-control
techniques:
- T1071
- name: Social Engineering Lure Delivery
observables:
- /cf.js
- /api/css.js
- /api/index.php
- BSOD lure
- reCAPTCHA lure
- Cloudflare Turnstile lure
slug: clickfix-lure-delivery
tactic: execution
techniques:
- T1071
- name: Malicious Clipboard Injection
observables:
- PowerShell command copied to clipboard
slug: clipboard-command-injection
tactic: collection
techniques:
- T1115
- name: User-Executed PowerShell Payload
observables:
- powershell.exe
- Net.WebClient download
- mode=download
slug: powershell-payload-execution
tactic: execution
techniques:
- T1059.001
- name: Infostealer Data Theft
observables:
- Vidar
- Stealc
- Remus
- Salat
slug: infostealer-credential-access
tactic: credential-access
techniques:
- T1555
summary: ErrTraffic is a Malware-as-a-Service (MaaS) framework that compromises
WordPress sites to distribute infostealers using the 'ClickFix' social engineering
technique. It uses the EtherHiding technique to resolve its command-and-control
infrastructure via blockchain smart contracts and delivers malicious PowerShell
commands that victims are tricked into executing manually.
series:
index: 2
slug: errtraffic-a-growing-clickfix-malware-distribution-framework
title: 'ErrTraffic: A Growing ClickFix Malware Distribution Framework'
total: 2
severity: high
targets:
analyst:
name: Tier-2 analyst
role: analyst
endpoint:
category: endpoint
name: Endpoint telemetry (hb_ surfaces)
telemetry:
- endpoint
hunter:
agent: true
name: Hunt agent
tlp: clear
type: investigation
---
# ErrTraffic ClickFix PowerShell and Infostealer Activity
This hunt identifies the endpoint manifestations of the ErrTraffic framework, a Malware-as-a-Service (MaaS) system that uses ClickFix social engineering. It targets the execution of PowerShell commands containing specific download parameters, correlates this with unauthorized access to browser credential stores by non-browser processes, and identifies DNS activity targeting blockchain-resolved C2 infrastructure.
## dns-to-errtraffic-c2
<!-- DNS lookups to ErrTraffic C2 -->
Identify hosts resolving domains associated with the ErrTraffic framework to narrow the estate for behavioural queries.
```sqlite target=endpoint role=scoping params=(c2_domains=c2_domains, lookback_days=lookback_days)
~~~yaml
expected: Hosts resolving known C2 domains. Silence indicates no direct resolution
of the provided domains, which may occur if the attacker rotates blockchain-derived
infrastructure.
reads:
- device_hostname
- query_hostname
- process_name
- time
silence: not_evidence_of_absence
source: hb_dns_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, query_hostname, process_name, time FROM hb_dns_activity WHERE instr(',' || '{{c2_domains}}' || ',', ',' || LOWER(query_hostname) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')
```
## corroborate
<!-- Corroborate ClickFix execution and harvesting -->
parallel:
- → powershell-clickfix-execution
- → rare-credential-file-access
join: → triage-infection
## powershell-clickfix-execution
<!-- PowerShell execution with ClickFix lures -->
Find PowerShell commands containing the specific download parameters and lure markers described in the report.
```sqlite target=endpoint role=detection-candidate params=(powershell_binaries=powershell_binaries, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
expected: Process rows showing PowerShell used with ClickFix download markers. Silence
means no such commands were executed within the window.
reads:
- device_hostname
- process_name
- process_cmd_line
- user_name
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE (instr(',' || '{{powershell_binaries}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND LOWER(process_cmd_line) LIKE '%mode=download%' AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days')
```
## rare-credential-file-access
<!-- Rare process access to browser data -->
Identify non-browser processes reading sensitive browser credential files to establish harvesting behaviour.
```sqlite target=endpoint role=baseline params=(credential_file_names=credential_file_names, legitimate_browsers=legitimate_browsers, scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
compare: first_seen
window: '{{lookback_days}}d'
expected: A process that is not a browser reading browser databases. Silence suggests
no suspicious harvesting occurred on those hosts.
prevalence:
by: device_hostname
key:
- process_name
rare_below: 3
reads:
- device_hostname
- process_name
- file_name
- file_path
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-09-28'
~~~
SELECT device_hostname, process_name, file_name, file_path, COUNT(*) AS access_count, MIN(time) AS first_seen FROM hb_file_activity WHERE instr(',' || '{{credential_file_names}}' || ',', ',' || LOWER(file_name) || ',') > 0 AND NOT (instr(',' || '{{legitimate_browsers}}' || ',', ',' || LOWER(process_name) || ',') > 0) AND ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY device_hostname, process_name, file_name, file_path HAVING access_count < 50
```
## triage-infection
<!-- Triage ErrTraffic infection -->
```agent target=hunter
cite: required
context:
- dns-to-errtraffic-c2
- powershell-clickfix-execution
- rare-credential-file-access
max_iterations: 4
objective: Determine if a host was compromised by an ErrTraffic lure and if credential
harvesting occurred.
success_criteria: A per-host verdict that identifies the malicious binary responsible
for file access and its origin via PowerShell.
tools:
- endpoint
```
## route-on-verdict
<!-- Route on verdict -->
if~: "the triage-infection verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: missing-endpoint-telemetry)
else: → close-out
## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the endpoint from the network and revoke any active cloud sessions for the affected user.
```
→ analyst-review
## analyst-review
<!-- Analyst forensic review -->
```manual target=analyst
Review the cited rows from the triage step. Verify the binary that accessed the credential stores. Search for other persistence mechanisms installed by the payload.
```
→ close-out
## close-out
<!-- Hunt closure -->
```manual target=analyst
Record the results of the hunt. If new C2 domains were identified during forensic review, update the c2_domains parameter for future runs.
```
→ end
Run it
Take this hunt into your environment.
Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.
Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.