Malware-as-a-Service Framework Exvicy Has Emerged
A new framework uses deceptive browser prompts to compromise WordPress sites, marking a rise in subscription costs.
Updated on Sept. 22, 2026 in Cybersecurity

Live Poll
Is the increasing availability of sophisticated malware tools a serious risk to your personal digital security?
The Exvicy malware-as-a-service framework has been identified as a new threat that leverages compromised WordPress websites for distribution. The platform, which has recently raised its monthly subscription price, incorporates stolen code from a rival service.
Why it matters
The emergence of Exvicy highlights how malware developers are increasingly recycling existing code while scaling their operations via subscription-based models. This shift toward formalized malware-as-a-service reflects a professionalizing threat landscape that prioritizes operational efficiency.
The Exvicy framework maintains a recurring monthly subscription fee of $2,000, which represents a 67% price increase over the service's initial $1,200 rate. The infrastructure relies on two hardcoded command and control servers to direct its operations.
The players
Exvicy
A subscription-based malware framework that utilizes stolen code and social engineering to compromise host environments.
ErrTraffic
A rival malware-as-a-service provider whose existing code was integrated into the Exvicy platform.
The details
Exvicy functions as a ClickFix framework, a method that uses social engineering to trick users into executing malicious code. The platform injects obfuscated JavaScript—code masked to prevent detection—into vulnerable WordPress sites to display a fake Cloudflare Turnstile human-verification prompt. If a visitor interacts with the prompt, they are instructed to press Win+R and execute a provided command, which pulls additional malware from the hardcoded command servers to complete the infection.
Timeline
September 22, 2026: The Exvicy malware framework was identified in operation.
The Tech Race
Exvicy's adoption of the ClickFix delivery method follows a documented industry trend of using fake verification prompts to bypass automated security filters. By integrating stolen code from services like ErrTraffic, the platform prioritizes rapid deployment over original development in the competitive market for cybercrime tools.
WordPress administrators should immediately audit their sites for unauthorized JavaScript injections and ensure all plugins are updated to mitigate the risk of hosting malicious prompts. Users encountering suspicious verification prompts that ask for keyboard-based commands should close their browser window immediately.
The takeaway
The maturation of Exvicy into a premium-priced service indicates a growing market demand for accessible, pre-packaged malware tools. Security teams should monitor the Exploit.IN forum to track potential shifts in the framework's pricing or capabilities as the developers continue to iterate.
Further reading
For broader trends in emerging digital threats, visit our Cybersecurity section.
Live Poll
Is the increasing availability of sophisticated malware tools a serious risk to your personal digital security?






