PolygonMcAfeeMITREProofpointGoogleCloudflareBitdefenderKasperskySentinelOneSophosMicrosoftWordPressCrowdStrikeErrTraffic

Fake CAPTCHA pages push malware that kills 145 security processes; attackers use signed vulnerable driver to disable endpoint defenses

Hackers are exploiting fake CAPTCHA pages to deploy malware that disables 145 security processes, using a signed vulnerable driver to bypass defenses. This sophisticated attack chain involves compromised WordPress sites and user-executed PowerShell commands, leading to the installation of the Cruciferra loader and Remus information stealer.

CyberSecurityNews CyberSecurityNews+1 source20 August 2026 · 19:25 UTC
CuriousCats Full Story

Hackers are leveraging fake CAPTCHA pages to distribute a malware loader that can disable 145 security processes, significantly enhancing their attack capabilities. This campaign, which utilizes compromised WordPress sites, tricks victims into executing malicious PowerShell commands, thereby bypassing traditional security measures.14

The operation employs ErrTraffic, a malware delivery service that creates deceptive ClickFix lures mimicking Google reCAPTCHA or Windows error screens. Victims are directed to these pages, where they unknowingly run a PowerShell command that initiates the infection chain.3

Once the command is executed, the Cruciferra loader is installed through a legitimate Microsoft-signed program, which then uses process hollowing to inject the Remus information stealer into a trusted process, ServiceModelReg.exe. This technique, tracked by MITRE ATT&CK as T1574.001, allows the malware to operate under the guise of a legitimate application, evading detection by security software.567

The campaign's sophistication is underscored by its ability to convince users to execute the infection chain themselves, a method that circumvents controls focused solely on malicious downloads. ErrTraffic is marketed as a service by an actor known as LenAI, reportedly costing $380 per month, and includes features for lure customization and campaign analytics.

This attack highlights the evolving tactics of cybercriminals, who are increasingly using social engineering to exploit human behavior in their malware distribution strategies.

Key Insight
“The campaign leverages ErrTraffic, a malware-as-a-service platform sold for $380 per month, and uses Polygon smart contracts to rotate command servers. Cruciferra's EDR killer abuses a signed but vulnerable driver, DCRCVDrv.sys, to terminate processes from Microsoft, CrowdStrike, SentinelOne, and others.”
CuriousCats studied:
1
CyberSecurityNewsCyberSecurityNews
“Hackers are using fake CAPTCHA pages to push a malware loader that can shut down security software before a follow-on payload runs.”
CyberSecurityNews →
2
gbhackers.comgbhackers.com
“Threat actors are pairing fake CAPTCHA verification pages with a commercial malware loader capable of disabling endpoint defenses, creating a high-impact infection chain that begins with a victim manually executing a malicious PowerShell command.”
gbhackers.com →
Ask CuriousCats
What is ErrTraffic used for?
Who developed the Cruciferra EDR killer?
How does DCRCVDrv.sys affect security processes?
Are other malware platforms using smart contracts?
How do current threats compare to previous attacks?
Get your CIA-level briefing,
in real time.
CuriousCats monitors the internet every minute for you and brings you the most personalized brief of videos, social media posts, news and more.
Download the App
One story brought you here.
CuriousCats brings you everything else worth knowing.
Get CuriousCats