A new Malware-as-a-Service (MaaS) platform called Exvicy has surfaced on the Russian-language cybercrime forum Exploit.IN, and researchers say it’s a near-identical clone of an established ClickFix distribution framework.
Sekoia’s Threat Detection & Research (TDR) team traced the operation from a single forum screenshot to live command-and-control infrastructure, compromised WordPress sites, and code that mirrors the rival ErrTraffic framework almost line for line.
The threat actor known as @Exvicy began advertising the panel on May 26, 2026, priced it at $1,200 per month, then raised it to $2,000 in mid-August, citing rising detection rates. Multiple forum members vouched for the service’s reliability in the weeks that followed.
Exvicy Exposed: New ClickFix Malware Kit
TDR analysts spotted a partially redacted domain in a screenshot of the admin panel’s domain-management tab. The visible portion showed the domain used Cloudflare’s nameserver pair randy.ns.cloudflare.com and stevie.ns.cloudflare.com.
Searching for similarly configured domains registered after mid-May turned up five matches, including us-addnewdevice.com and cloudflarecapcha.com, all registered through FewMoreTaps and PublicDomainRegistry with Google Trust Services certificates.

One of these domains hosted a login page visually identical to Exvicy’s advertised admin panel, plus an obfuscated PowerShell downloader fetching an MSI installer for PuTTY from a Cloudflare R2 bucket matching a payload file the operator had shown in forum screenshots.
Exvicy operates by injecting obfuscated JavaScript into hacked WordPress sites. The script builds a full-screen iframe disguised as a Cloudflare Turnstile “Security Check,” then loads a fake verification page instructing victims to press Win+R, paste, and hit Enter, executing a malicious PowerShell one-liner copied silently to the clipboard.
The lure is localized into 13 languages and communicates victim status back to the C2 through a /api.php endpoint using dl, cb, and check actions to track infection progress in near real time.
The most striking finding is code-level overlap with ErrTraffic, a ClickFix framework sold by @LenAI since December 2025 that popularized EtherHiding, hiding C2 addresses on the Polygon blockchain.
Side-by-side comparisons show Exvicy’s injected script and ClickFix HTML reuse ErrTraffic’s FNV-1a hashing routine, UUID generation, clipboard-hijacking function, anti-debugging checks, and 13-language translation logic almost verbatim, differing mainly in variable obfuscation.
The key advertised differentiator Exvicy uses “Win+R” while ErrTraffic uses “Win+X” appears to be cosmetic.
Sekoia assesses with high confidence that Exvicy’s developer either purchased or leaked ErrTraffic’s source, or scraped and reverse-engineered its client-side code from compromised sites, then built a simpler backend without blockchain-based C2 concealment.

Sekoia confirms telemetry showing hosts across multiple customer environments already communicating with Exvicy’s C2 servers, indicating the framework has moved beyond forum advertising into active deployment.
With ClickFix-style social engineering abusing fake CAPTCHA and verification prompts to trick users into running malicious commands, Exvicy adds another fast-growing entrant to an increasingly commoditized cybercrime market, alongside frameworks like ClearFake, KongTuke, and SmartApeSG.
Sekoia says it will continue tracking Exvicy’s infrastructure alongside ErrTraffic and related ClickFix operations as they evolve.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.