A New Malware-as-a-Service Platform: Exvicy
Recent intelligence has unveiled a novel Malware-as-a-Service (MaaS) platform, known as Exvicy, which capitalizes on compromised WordPress sites to distribute deceptive ClickFix lures that masquerade as Cloudflare Turnstile verification pages.
According to researchers at Sekoia, there is substantial confidence that Exvicy is an imitation of the widely recognized ErrTraffic framework.
It appropriates key components including JavaScript injection methods, counterfeit verification codes, and command-and-control (C2) communication protocols.
Initially, the actor leasing this framework did so for a fee of $1,200 per month. Subsequently, in August, the rate escalated to $2,000, with the operator attributing the increase to the incessant need for updates in response to heightened detection efforts.
The service encompasses an administration panel along with JavaScript tools intended to convert compromised sites into channels for malware dissemination.
Utilizing a screenshot located within the sales thread, Sekoia’s Threat Detection and Research team traced the operational footprint of Exvicy.
This image revealed a segment of the Exvicy administration interface alongside a partially obscured domain managed by Cloudflare.
Strategically pivoting from the visible DNS settings and the timing of registration, researchers successfully identified domains associated with the operator, including:
- us-addnewdevice[.]com
- cloudflarecapcha[.]com
- perfectverified[.]com
- newsecuredevice[.]com
- unitedstateverif[.]com
This infrastructure is utilized to host Exvicy panel pages, PowerShell payloads, and counterfeit Cloudflare verification content.
Additionally, researchers detected a downloader hosted through the identified infrastructure, which retrieved an MSI payload from a Cloudflare R2 bucket.
Notably, in one recorded instance, the installer executed the legitimate PuTTY SSH client, indicating the framework’s capability to distribute various payloads rather than being confined to a singular malware variant.
The infection cascade initiates with the injection of an obfuscated JavaScript snippet into a compromised WordPress website.
As reported by Sekoia, Exvicy was first promoted on the Russian-speaking Exploit. cybercrime forum on May 26, 2026, by an operator identified as @Exvicy.
Exvicy ClickFix Malware
The injected code employs Base64 encoding, XOR encryption, and randomized variable nomenclature to obfuscate its operation. Login page and administration panel associated with Exvicy (Source: Sekoia).
Once the code is decoded within a visitor’s browser, it generates a full-screen iframe labeled “Security Check,” engages with the Exvicy infrastructure, and loads the subsequent ClickFix page.
This resulting bait impersonates a Cloudflare Turnstile CAPTCHA. Rather than exploiting a browser vulnerability, it deftly encourages victims to unwittingly execute the malicious payload themselves.
The page instructs users to press “Win+R,” utilize “Ctrl+V” to paste clipboard content, and hit Enter. These keystrokes trigger the Windows Run dialog, executing a PowerShell command provided by the attacker.
Notably, Exvicy accommodates commands in 13 different languages, enhancing the campaign’s potential reach across diverse regions.
Moreover, the payload is automatically copied to the clipboard and typically retrieves an additional remote PowerShell script for execution.
Sekoia’s findings revealed C2 communications intended to register potential victims, capture telemetry from browsers and operating systems, monitor fraudulent CAPTCHA interactions, and verify whether a victim had executed the harmful command.
The platform also meticulously logs visitor activities and interactions, affording affiliates valuable insight into conversion metrics.
Exvicy claims a distinction from ErrTraffic through its use of the Win+R shortcut in place of Win+X.
However, Sekoia’s analysis uncovered that the two frameworks share a plethora of pertinent code: identical FNV-1a-based deduplication logic, UUID generation protocols, clipboard manipulation functions, translation capabilities, anti-analysis measures, C2 request protocols, and status polling workflows.
Significantly, the primary distinction resides in C2 handling; ErrTraffic employs EtherHiding, embedding C2 information within Polygon blockchain smart contracts, whereas Exvicy hardcodes its C2 servers directly within the injected script.
Since its inception in December 2025, ErrTraffic has gained a reputation for injecting harmful JavaScript into WordPress sites to serve ClickFix enticements.
Sekoia’s telemetry has pinpointed hosts across several client environments actively communicating with Exvicy C2 servers, corroborating that threat actors are operationalizing this service.
It is imperative for defenders to monitor WordPress environments for unexpected injected JavaScript, suspicious outgoing browser requests to verification domains, clipboard-based PowerShell executions, and unusual requests targeting paths such as /embed/, /api.php, and /panel/html-event/.

Organizations should also educate users that genuine CAPTCHA checks never necessitate the opening of the Run dialog, pasting commands, or executing PowerShell scripts.
Indicators of Compromise (IOCs)
| Domains | First Seen Date |
|---|---|
kawaiininjaclub[.]cfd | 2026-08-23 |
jouncepopdownloadnow[.]com | 2026-08-19 |
jumppopdownloadsecret[.]monster | 2026-08-19 |
lastdayornot[.]top | 2026-08-19 |
searlepub[.]com | 2026-08-18 |
whirlpoploaderfast[.]com | 2026-08-16 |
Source link: Gbhackers.com.





