Keypoints
- The campaign leveraged the ErrTraffic ClickFix malware distribution framework.
- Sekoia identified 71 domain IoCs and extracted additional network-related artifacts from the campaign.
- The activity focused on WordPress servers and used a built-in TDS function.
- The operators concealed command-and-control infrastructure within the blockchain.
- Fake AI tools such as Google Antigravity and ChatGPT were used as lures.
- Researchers believed LenAI, a known MaaS operator, may be behind the attacks, though the two studied clusters were likely run by different threat actors.
- DNS and WHOIS analysis revealed malicious IPs, email-connected domains, typosquatting groups, and historical domain-to-IP resolutions tied to the infrastructure.
MITRE Techniques
- [T1566 ] Phishing – Used fake AI tools as lures to entice victims into engaging with the campaign (‘utilized fake AI tools (e.g., Google Antigravity and ChatGPT) as lures’).
- [T1583.001 ] Acquire Infrastructure: Domains – The infrastructure relied on numerous registered domains for campaign operations (‘we extracted 71 domains’).
- [T1583.004 ] Acquire Infrastructure: Server – The campaign used server infrastructure hosted across multiple IPs and domains for distribution and C&C (’16 unique IP addresses’).
- [T1071.001 ] Application Layer Protocol: Web Protocols – The campaign communicated through web-based domain infrastructure and DNS activity tied to the clusters (’45 DNS queries’).
- [T1036 ] Masquerading – Typosquatting and look-alike domains were used to imitate legitimate services or brands (‘appeared in two typosquatting groups’ / ‘bulk-registered with four look-alike domains’).
- [T1090 ] Proxy – C&C infrastructure was concealed within blockchain-related infrastructure to obscure direct communication paths (‘concealed their C&C infrastructure within the blockchain’).
- [T1047 ] Windows Management Instrumentation – Not mentioned in the article.
Indicators of Compromise
- [Domain ] Campaign infrastructure and typosquatting domains – finework[.]top, sandman[.]bond, and 2 more malicious domains
- [Domain ] Historical resolution artifacts from the ErrTraffic investigation – webanalytics-cdn[.]sbs, abrikos[.]xyz, and 68 more domains with historical DNS data
- [IP Address ] Client and malicious infrastructure identified through DNS and threat-intel analysis – 8 unique client IPs, 16 unique IP addresses
- [Email Address ] Historical WHOIS email contacts used to discover connected domains – 2 public email addresses
- [Email-Connected Domains ] Domains found via reverse WHOIS from public email addresses – 12 unique email-connected domains
- [ASN ] Network attribution for communicating clients – four distinct ASNs
- [DNS Queries ] Network activity observed between clients and domains – 45 DNS queries between 20 April and 15 June 2026
Read more: https://circleid.com/posts/a-dns-investigation-of-lenais-errtraffic-clickfix-distribution-network