Exvicy Malware Service Has Emerged Online

A new malicious framework is targeting WordPress sites by mimicking security checks.

Updated on Sept. 22, 2026 in Cybersecurity

Exvicy Malware Service Has Emerged Online

Live Poll

Is the increasing availability of sophisticated malware tools a serious risk to your personal digital security?

A new malware-as-a-service framework known as Exvicy has emerged, utilizing stolen code to target users via compromised WordPress websites. The service functions as a ClickFix framework that tricks victims into running malicious commands on their own machines.

Why it matters

The framework represents an evolution in cyber threats by leveraging fake security prompts to bypass user skepticism. By incorporating stolen code from a rival service, the developers have rapidly scaled their operations to target a global audience.

The Exvicy framework utilizes two hardcoded command servers to control operations and includes victim instructions translated into 13 different languages. It specifically operates by injecting obfuscated JavaScript into WordPress sites to display a fake Cloudflare Turnstile verification.

The players

Exvicy

This is a new malware-as-a-service framework that uses ClickFix tactics to distribute malicious software.

ErrTraffic

This is a rival malware service that had its source code stolen and incorporated into the Exvicy framework.

Exploit.IN

This is an online forum used by cybercriminals to advertise and trade malicious services and tools.

The details

Exvicy uses a deceptive tactic that prompts victims to press Win+R and execute a command from a run dialog box to complete a fraudulent security check. The service is actively advertised on the Exploit.IN forum, where it has integrated code stolen from a competing service called ErrTraffic.

Timeline

  1. The Exvicy framework was reported to have emerged on September 22, 2026.

The Tech Race

Exvicy follows the established pattern of the rise of ClickFix malware-as-a-service frameworks that rely on social engineering rather than traditional software exploits. This evolution demonstrates a clear shift in how cybercriminals are moving away from developing proprietary tools toward reusing stolen code for rapid market deployment.

Users can protect themselves by avoiding unexpected security prompts that ask them to open Windows run dialog boxes or execute manual commands. Site administrators should prioritize securing WordPress installations to prevent them from being used as distribution points for these fake verification checks.

The takeaway

The emergence of Exvicy highlights the growing danger of malware frameworks that weaponize common security check habits. Users should remain skeptical of any website that requests manual command line execution as a prerequisite for browsing.

Further reading

For more information on emerging digital threats, visit the Cybersecurity section.

Live Poll

Is the increasing availability of sophisticated malware tools a serious risk to your personal digital security?