ErrTraffic Service Enables ClickFix Attacks via Fake Browser Glitches

Related

CISA Warns RESURGE Malware Can Remain Dormant on Ivanti EPMM Devices

What happened The U.S. Cybersecurity and Infrastructure Security Agency (CISA)...

UK Warns of Iranian Cyberattack Risks Amid Middle East Conflict

What happened The UK National Cyber Security Centre (NCSC) issued...

CISOs to Watch in Massachusetts’ Insurance Industry

Massachusetts’ insurance sector includes regional carriers, global specialty insurers,...

CISOs to Watch in Massachusetts’ Financial Services Industry

Massachusetts’ financial services ecosystem blends global asset managers, insurers,...

Cybersecurity Leaders to Watch in Massachusetts’ Banking Industry

Massachusetts’ banking sector spans community banks, regional institutions, global...

Share

What happened

The ErrTraffic service enables ClickFix attacks by generating fake browser error messages on compromised websites to trick users into running malicious commands, leading to malware installation. The tool is sold as a service and supports multiple operating systems, including Windows, macOS, Linux, and Android.

Who is affected

Organizations with public-facing websites and users who visit compromised pages are at risk. Attackers can abuse trusted sites to distribute malware, potentially leading to credential theft, data compromise, and endpoint infections inside corporate environments.

Why CISOs should care

ClickFix attacks blend social engineering with technical deception, bypassing traditional phishing defenses. This technique increases the likelihood of user-initiated compromise from otherwise legitimate websites, expanding the attack surface beyond email-based threats.

3 practical actions

  1. Web integrity monitoring: Detect unauthorized script injections or page behavior changes on corporate websites.
  2. User awareness training: Educate users to distrust browser prompts requesting manual command execution.
  3. Endpoint execution controls: Restrict unauthorized script and command execution on endpoints.