A new Malware-as-a-Service platform, Exvicy, is actively abusing compromised WordPress websites to deliver ClickFix lures disguised as Cloudflare Turnstile verification pages. Researchers at Sekoia assess with high confidence that the service is a copycat of the established ErrTraffic framework, reusing its JavaScript injection logic, fake-verification code, and command-and-control communication routines The actor initially rented the […]
Read the original article:
