Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

New malware campaign combines social engineering with defense evasion

A sophisticated malware-as-a-service campaign combines social engineering via compromised WordPress sites with advanced defense evasion. The attack chain uses obfuscated JavaScript to deliver deceptive lures, prompting victims to execute malicious PowerShell, which then sideloads the Cruciferra loader. This loader abuses a vulnerable driver (DCRCVDrv.sys) to terminate 145 security processes from the kernel, enabling the deployment of the Remus information stealer.
Read Full Article →

Malware New malware campaign combines social engineering with defense evasion August 20, 2026 Share By SC Staff (Adobe Stock) As outlined in Infosecurity Magazine, a recent malware-as-a-service (MaaS) campaign has emerged, effectively merging ClickFix social engineering tactics with the ErrTraffic delivery service and the Cruciferra loader. This sophisticated operation provides threat actors with a potent method for distributing malware while simultaneously disabling endpoint security processes on targeted systems, as reported by eSentire’s Threat Response Unit (TRU). The campaign, observed in late July 2026, begins with compromised WordPress websites injected with obfuscated ErrTraffic JavaScript. This script utilizes the Ethereum blockchain to resolve command-and-control (C2) addresses, subsequently retrieving JavaScript for deceptive lures such as fake Google reCAPTCHA, Cloudflare Turnstile, or a Blue Screen of Death. Victims are then prompted to copy and execute a malicious PowerShell command. Subsequent PowerShell stages employ a legitimate Microsoft-signed binary to sideload the Cruciferra DLL. This loader, marketed for its ability to disable antivirus and EDR processes, uses process hollowing to inject the Remus information stealer into another signed binary, ServiceModelReg.exe. The Cruciferra loader abuses a vulnerable driver, DCRCVDrv.sys, to terminate a list of 145 security-related processes from the Windows kernel, including most antivirus and EDR products. This combination of MaaS offerings allows attackers to outsource delivery, social engineering, and defense evasion, highlighting a growing trend in sophisticated cybercrime operations. Source: Infosecurity Magazine SC Staff Related Malware Inside the fourth wave of the Shai-Hulud npm worm Brad LaPorte August 20, 2026 The signed packages were authentic – but that’s precisely the problem: the provenance lied. Malware Grandoreiro banking trojan resurfaces with new campaign targeting Latin America SC Staff August 20, 2026 The latest campaign, observed in May 2026, utilizes DLL sideloading to execute the banking trojan. Black Hat Black Hat/DEF CON attendees targeted in malware scheme with Google Doc lure Laura French August 20, 2026 A malicious Google Apps Script sidebar leads to payloads for both macOS and Windows. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article