"detections are becoming daily," the operator using the handle Exvicy wrote in the Exploit.IN advert, according to Sekoia's analysis published on September 21.
A seller called Exvicy: launch date, pricing and the marketplace
Sekoia's Threat Detection & Research team traced a new ClickFix malware-as-a-service (MaaS) framework marketed by a Russian-speaking actor using the handle Exvicy. The actor has advertised the service on the Exploit.IN forum since May 26 and launched at $1,200 a month; the advertised price rose to $2,000 in mid‑August as the seller warned that "detections are becoming daily." Sekoia noted the seller contrasted Exvicy with a rival framework, ErrTraffic, which has been offered on the same forum since December 2025, and emphasized a user-facing difference: Exvicy's lure relies on the Win+R shortcut rather than ErrTraffic's Win+X.
From a forum screenshot to roughly 80 live panels
Sekoia found the operator's infrastructure by inspecting the advert itself. A screenshot in the post contained a redacted domain whose length, top-level domain and Cloudflare nameserver pair narrowed the search to five recently registered domains. One of those domains hosted a login page identical to the panel in the screenshot; a PowerShell downloader on that host fetched a file matching an entry in the operator's own payload list. Pivoting from that panel revealed 13 additional panels by July 9, and by late August Sekoia's list of hosts serving the panel ran to about 80.
Separately, telemetry from multiple customer environments showed hosts communicating with Exvicy command-and-control servers, which Sekoia says confirms threat actors are using the framework to deliver malware through compromised WordPress sites.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadHow the lure works: fake Cloudflare Turnstile, clipboard tactics and a three‑minute poll
The Exvicy framework injects obfuscated JavaScript into compromised WordPress sites. That script loads a fake Cloudflare Turnstile check and instructs victims—through pages localized in 13 languages—to press Win+R, paste and press Enter. The PowerShell command is already copied to the victim's clipboard; following the page's directions runs that command. The lure reports each step back to the operator, including when the victim clicks the fake checkbox, and then polls for three minutes to confirm the command executed.
Near‑identical code to ErrTraffic, and one technical divergence
Sekoia assessed with high confidence that Exvicy reuses ErrTraffic's code in both the injected script and the lure page. Aside from encoded payloads and randomized variable names, the injected scripts are nearly identical and the lure pages share the same clipboard, fingerprinting, anti‑analysis and polling functions. Sekoia further assessed with medium confidence that both operators use the same tool to generate the injected scripts.
The clearest technical difference is operational: ErrTraffic hides its command-and-control address on the Polygon blockchain using a technique Sekoia calls EtherHiding, while Exvicy hardcodes two servers. Sekoia judged the Exvicy developer most likely obtained ErrTraffic's source code either as a paying customer or via a leak; rebuilding a backend by scraping client-side code from infected sites was deemed less plausible because it would take as much effort as writing new code.
What this means for technologists, affected enterprises, and end users
- Technologists and security teams: prioritize detection for obfuscated JavaScript injected into WordPress pages, monitoring for the specific clipboard/PowerShell pattern described and for connections to the vendor‑hardcoded C2 servers Sekoia mapped.
- Affected enterprises and procurement leaders: recognize that compromised WordPress sites are being used as distribution points and that rival MaaS offerings can share or leak source code—so vet third‑party code, monitor site integrity and track panels matching the screenshot characteristics Sekoia identified.
- End users: the exploitation method relies on social engineering—fake Turnstile UI plus a clipboard trick and the Win+R shortcut—so users should be wary of on‑page prompts that ask them to run pasted commands.
Sekoia's findings tie active telemetry to a new MaaS offering whose operator appears to have built on a near‑duplicate rival's codebase. The combination of live C2 callbacks, a clear fingerprint in the injected script and a predictable user interaction sequence gives defenders concrete signals to hunt for—and raises a pointed question about how ErrTraffic's source code became available to a purported competitor. Read Sekoia's full write-up via the original story below.




