“The driver is not currently known to Microsoft or LOLDrivers, meaning it will not be caught by the vulnerable driver blocklist.” That single finding sits at the center of a late‑July 2026 campaign eSentire’s Threat Response Unit (TRU) described today — a coordinated chain that combines compromised websites, blockchain-resolved command-and-control, and a paid loader designed to stop security tooling in its tracks.
ErrTraffic JavaScript injected into compromised WordPress sites
eSentire observed the campaign beginning with compromised WordPress sites that contained an obfuscated ErrTraffic JavaScript injection. The injected script used the Ethereum blockchain to resolve a command-and-control (C2) address, then retrieved JavaScript that presented one of three lures to visitors: a fake Google reCAPTCHA, a fake Cloudflare Turnstile, or a Blue Screen of Death (BSOD) page.
Each lure copied a malicious PowerShell command to the victim’s clipboard and instructed the user to paste and run it — a social engineering technique known as ClickFix that has previously been delivered via compromised sites but here was combined with two separate MaaS offerings, according to the advisory.
ClickFix social engineering leading to a multi-stage PowerShell chain
When victims followed the lure instructions, additional PowerShell stages executed. Those stages used a legitimate Microsoft-signed binary to sideload a Cruciferra DLL. Cruciferra then employed process hollowing to inject the Remus information stealer into a second Microsoft-signed binary, ServiceModelReg.exe, according to eSentire’s write-up. The sequence moved from an Internet-delivered JavaScript lure to signed binary abuse and in-memory injection.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleCruciferra loader and the DCRCVDrv.sys kernel driver
Cruciferra is marketed on underground forums with a package described by eSentire as capable of disabling antivirus and endpoint detection and response (EDR) processes. The payload abused a signed, vulnerable driver called DCRCVDrv.sys to terminate security-related processes from the Windows kernel. eSentire found 145 process names configured for termination by default, most of them antivirus and EDR products.
Crucially, eSentire noted that the driver “is not currently known to Microsoft or LOLDrivers,” which means it will not be caught by the vulnerable driver blocklist. As a practical mitigation eSentire recommended blocking the driver directly by hash.
ErrTraffic and Cruciferra as distinct MaaS offerings
Rather than a single, monolithic toolkit, the campaign combined two separately marketed services. ErrTraffic was advertised at $380 per month and provided operators with customizable ClickFix templates, campaign statistics, filtering and a WordPress plugin generator. Its use of blockchain-based infrastructure allowed operators to rotate C2 domains without changing the JavaScript injected into compromised websites.
Cruciferra’s so‑called EDR‑killing package cost $1,200 per month and is promoted as a loader capable of disabling security products. The eSentire advisory framed the operation as an example of how operators can outsource delivery, social engineering and defense‑evasion — buying modular capabilities rather than building them in‑house.
What this means for security teams, site operators and end users
- Security teams: eSentire’s technical notes point to concrete artefacts to monitor: the use of Microsoft-signed binaries for sideloading, process hollowing into ServiceModelReg.exe, the Remus information stealer payload, and the presence of a signed driver named DCRCVDrv.sys configured to kill 145 process names by default. Blocking that driver by hash is the specific mitigation eSentire recommended.
- Site operators and hosting providers: compromised WordPress sites were the initial delivery platform, hosting obfuscated ErrTraffic JavaScript. Operators should scan for injected JavaScript, unexpected plugin generators or templates, and any blockchain-resolving scripts that retrieve C2 addresses without visible domain changes.
- End users: the attack relies on a basic social engineering step — pasting and running a PowerShell command copied from a browser prompt. The lure presented itself as routine site verification (reCAPTCHA/Turnstile) or a dramatic error (BSOD), but in every case the instruction was to execute a PowerShell command placed on the clipboard.
eSentire’s advisory offers a compact technical spine: compromised WordPress sites → ErrTraffic JavaScript using Ethereum for C2 resolution → ClickFix lures that prompt users to run PowerShell → Microsoft-signed binary sideloading of Cruciferra → kernel driver abuse to terminate EDR/AV processes and the in-memory injection of Remus. The campaign’s novel angle is not a single breakthrough exploit but the combination of modular, paid services — each filling a distinct role in delivery, social engineering and defense evasion.
For defenders the immediate, actionable detail is precise: the DCRCVDrv.sys driver is not listed in Microsoft’s or LOLDrivers’ known vulnerable-driver blocklists, and eSentire’s recommendation is to block it by hash. Beyond that concrete step, the advisory demonstrates how price‑tagged MaaS components can be chained to build a full attack life cycle without bespoke tooling.
Source: https://www.infosecurity-magazine.com/news/maas-clickfix-errtraffic-cruciferra/




