The attack combines ClickFix social engineering, blockchain-based EtherHiding, and dynamic infrastructure delivery to make detection and takedown more difficult This article explores research watchguard threat. . According to research by WatchGuard Threat Lab member Euler Neto, ErrTraffic operators use Polygon blockchain smart contracts to store or resolve malicious infrastructure rather than placing command-and-control (C2) addresses directly inside injected website code.
WatchGuard telemetry also identified additional payload variants, DLL side-loading activity, browser-targeting behavior, and techniques designed to weaken endpoint defenses. ErrTraffic was allegedly endorsed by user "LenAI." The framework features a traffic distribution system (TDS), allowing affiliates to filter visitors, route targeted users to specific payloads, and track delivery activity. Instead of embedding a static malicious domain, the injected code queries Polygon blockchain via remote procedure call (RPC) services.
Due to the decentralized nature and persistence designed into blockchain data, defenders cannot simply shut down a traditional hosting server to disrupt operations. Victims might encounter fake Cloudflare Turnstile or reCAPTCHA prompts asking them to paste a supposed verification command into Windows Run, PowerShell, or Command Prompt. The URLs used in these attacks include parameters related to browser type, referral sites, Cloudflare, or reCAPTCHA lures, indicating how ErrTraffic tailors its delivery to each victim session.
It also interacted with the Adobe Create PDF extension, which has been linked to CVE-2026-48294, a cross-origin data disclosure flaw affecting certain versions of the extension.












