www.infosecurity-magazine.com 21 Sept 2026, 14:30 UTC

Exvicy Malware Service Tricks WordPress Visitors Into PowerShell Attacks

Exvicy Malware Service Tricks WordPress Visitors Into PowerShell Attacks

A new malware-as-a-service framework called Exvicy is being used to deliver malware through compromised WordPress sites, according to Sekoia’s Threat Detection & Research team. Telemetry from multiple customer environments showed hosts communicating with Exvicy command-and-control servers, confirming active use by threat actors. A Russian-speaking operator using the Exvicy handle has advertised the service on the Exploit.IN forum since 26 May 2026. Its monthly price rose from $1,200 to $2,000 in mid-August.

Exvicy uses obfuscated JavaScript injected into compromised websites to display a fake Cloudflare Turnstile verification page. Victims are instructed to press Win+R, paste a command copied to their clipboard and press Enter, causing a PowerShell command to run. The lure supports 13 languages and reports user activity to the operator, including interaction with the fake verification box; it then polls for three minutes to check whether the command executed.

Sekoia traced the service from infrastructure details visible in an advert screenshot, finding around 80 hosts serving its administration panel by late August.

Sekoia assessed with high confidence that Exvicy reuses ErrTraffic’s code in both its injected script and lure page, including clipboard, fingerprinting, anti-analysis and polling functions. It assessed with medium confidence that both services use the same script-generation tool. The main technical difference is that ErrTraffic hides its command-and-control address on the Polygon blockchain, whereas Exvicy hardcodes two servers. Sekoia said the developer most likely obtained ErrTraffic’s source code either as a paying customer or through a leak.

View full article

Article by CyberSIXT