- Hackers are using fake CAPTCHA pages to push a malware loader that can shut down security software before a follow-on payload runs.
- The campaign combines compromised WordPress websites, a familiar browser verification prompt, and a Windows command that victims are persuaded to execute themselves.
- ErrTraffic, a malware delivery service, creates ClickFix lures styled as Google reCAPTCHA, Cloudflare Turnstile, or a Windows error screen.
- A visitor who follows the on-screen steps unknowingly runs a copied PowerShell command, opening the door to the Cruciferra loader and the Remus information stealer.
- Cruciferra uses a signed vulnerable driver to terminate 145 security-related processes, including those associated with Microsoft Defender and CrowdStrike.
- The loader then injects the Remus information stealer into a legitimate process, further compromising the victim's system.
- The impact is serious because Cruciferra is designed to blind a device before more harmful activity begins.
- This is a bring-your-own-vulnerable-driver technique, in which attackers use a real signed driver rather than an obviously malicious kernel component.
- Defenders should block the identified driver by hash in their security console and keep Microsoft’s vulnerable-driver protections enabled.
Hackers are leveraging fake CAPTCHA pages to distribute a malware loader that can disable 145 security processes, significantly enhancing their attack capabilities. This campaign, which utilizes compromised WordPress sites, tricks victims into executing malicious PowerShell commands, thereby bypassing traditional security measures.14
The operation employs ErrTraffic, a malware delivery service that creates deceptive ClickFix lures mimicking Google reCAPTCHA or Windows error screens. Victims are directed to these pages, where they unknowingly run a PowerShell command that initiates the infection chain.3
Once the command is executed, the Cruciferra loader is installed through a legitimate Microsoft-signed program, which then uses process hollowing to inject the Remus information stealer into a trusted process, ServiceModelReg.exe. This technique, tracked by MITRE ATT&CK as T1574.001, allows the malware to operate under the guise of a legitimate application, evading detection by security software.567

The campaign's sophistication is underscored by its ability to convince users to execute the infection chain themselves, a method that circumvents controls focused solely on malicious downloads. ErrTraffic is marketed as a service by an actor known as LenAI, reportedly costing $380 per month, and includes features for lure customization and campaign analytics.
This attack highlights the evolving tactics of cybercriminals, who are increasingly using social engineering to exploit human behavior in their malware distribution strategies.
“The campaign leverages ErrTraffic, a malware-as-a-service platform sold for $380 per month, and uses Polygon smart contracts to rotate command servers. Cruciferra's EDR killer abuses a signed but vulnerable driver, DCRCVDrv.sys, to terminate processes from Microsoft, CrowdStrike, SentinelOne, and others.”








