securityonline.info 8/27/2026, 9:32:18 AM · external

Cruciferra malware hijacks Windows PCs via hacked WordPress sites

Cruciferra malware hijacks Windows PCs via hacked WordPress sites
CyberSIXT Evidence Panel
Primary Source esentire.com

THE article discusses the Cruciferra malware loader, which is active in ClickFix campaigns targeting Windows users through compromised WordPress sites. This malware, found by eSentire, leverages techniques like DLL sideloading and process hollowing to execute malicious code and disable security measures. Key tactics include tricking users into executing PowerShell commands and employing a signed but vulnerable driver to terminate antivirus and endpoint detection and response (EDR) processes.

The malware is part of a broader crimeware service, sold monthly to attackers. Employing blockchain technology, ErrTraffic obscures its command-and-control operations, complicating defense efforts. Recommendations to mitigate this threat include monitoring for suspicious DLL loading, blocking untrusted PowerShell commands, and keeping systems updated.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline