Fast Facts
- The ErrTraffic campaign utilizes concealed C&C infrastructure within blockchain and fake AI tools as lures, increasing stealth and deception.
- Multiple domains involved show signs of typosquatting and malicious intent, with some registered months before detection, indicating premeditated operational planning.
- Nearly half of the identified IPs are confirmed malicious, highlighting persistent, widespread threat activity targeting WordPress servers and DNS infrastructure.
Threat Overview, Attack Techniques, and Targets
Recent analysis by Sekoia threat researchers uncovered a campaign that uses the ErrTraffic ClickFix malware distribution framework. They identified 71 domains associated with this network. The campaign appears to be linked to LenAI, a noted MaaS operator on the Dark Web. Two clusters, named Analytics and Beer, targeted WordPress servers. These clusters had built-in TDS functions and housed their command-and-control (C&C) infrastructure within blockchain networks. They also used fake AI tools like Google Antigravity and ChatGPT as lure tactics. While LenAI is implicated, researchers believe that other threat actors launched the studied clusters. LenAI also previously operated the Aeternum botnet.
Our DNS investigation provided more details. We found eight client IP addresses communicating with six domain IoCs through 45 DNS queries from April to June 2026. Many of these domains were involved in typosquatting groups, and some appeared in malicious domain feeds long before detection. Additionally, several domains were registered with malicious intent and connected to numerous IP addresses and domains. This information confirms the campaign’s complex and malicious infrastructure, primarily targeting web services and DNS systems.
Impact, Security Implications, and Remediation Guidance
The campaign’s infrastructure indicates a significant threat to organizations using compromised WordPress servers or hosting similar domains. The use of blockchain for C&C and fake AI tools as lures suggests a sophisticated operation designed to evade detection and facilitate malware distribution. Disruption of these domains and IPs is critical to stopping follow-up malicious activities.
Given the details available, it is recommended to consult with your security vendors or relevant authorities for specific mitigation strategies. Immediate actions include monitoring DNS traffic for suspicious queries, blocking identified malicious domains and IPs, and conducting thorough investigations of related domain registrations and network activity. As this research only provides a snapshot, further guidance should be obtained from cybersecurity vendors and threat intelligence providers to adapt security controls effectively.
Expand Your Tech Knowledge
Stay informed on the revolutionary breakthroughs in Quantum Computing research.
Explore past and present digital transformations on the Internet Archive.
ThreatIntel-V1
