New 'Exvicy' ClickFix Toolkit Spreads Malware Through Hacked WordPress Sites
Security researchers at Sekoia have discovered a new cybercrime tool called Exvicy, sold on underground forums since May, which is being used to compromise WordPress websites and trick visitors into infecting their own computers. Exvicy is a 'ClickFix' style attack: it injects hidden code into hacked WordPress sites that displays a fake security check. Visitors are told to press a keyboard shortcut and paste a command, which unknowingly runs malicious software on their machine.
Sekoia's investigation found that Exvicy's code closely mirrors that of a rival service called ErrTraffic, suggesting the developer copied or reused significant portions of it rather than building the tool from scratch. Researchers traced the operator's infrastructure through a screenshot in the seller's own advertisement, which led them to dozens of related domains, eventually growing to around 80 websites hosting the fake verification pages. The lure pages support 13 languages and report each stage of victim interaction back to the attacker's servers, allowing operators to track infections in near real time.
This discovery highlights how quickly copycat malware tools spread once a technique like ClickFix proves profitable, and how compromised legitimate websites, including small business WordPress sites, can be repurposed as delivery points without the owner's knowledge.