Exvicy Malware-as-a-Service Framework Emerges with Stolen Code
A new malware-as-a-service (MaaS) framework called Exvicy has emerged, built using code stolen from a competing service called ErrTraffic. According to Infosecurity Magazine, Exvicy operates as a ClickFix framework, distributing malware through compromised WordPress websites.
The threat actors behind Exvicy advertise the service on the Exploit.IN forum, with prices increasing from $1,200 to $2,000 per month. The service injects obfuscated JavaScript into vulnerable WordPress sites, presenting users with a fake Cloudflare Turnstile check.
Victims are prompted to press Win+R, paste a command into the run dialog, and execute it, with instructions available in 13 languages. The framework reports each step back to the operator.