#DriveSurge
Aus dem Feed: ⟪ Cyberkriminelle kapern tausende vertrauenswürdige Webseiten für DriveSurge-Angriffe ⟫ https://www.it-daily.net/shortnews/drivesurge-angriffe-webseiten | #medien #design
➔ „Die Kampagne DriveSurge nutzt zTDS, FakeUpdates und Clipboard-Hijacking, um Besucher gekaperter …
DriveSurge-Angriffe: Cyberkriminelle kapern Webseiten
Die Kampagne DriveSurge nutzt zTDS, FakeUpdates und Clipboard-Hijacking, um Besucher gekaperter Webseiten unbemerkt mit Schadsoftware zu infizieren.
www.it-daily.net
June 8, 2026 at 10:58 AM
CTA member @silentpush.bsky.social on DriveSurge:
"What makes DriveSurge notable isn’t just the volume of its activity; it’s the sophistication of its infrastructure, the breadth of its targets, and the fact that it has been operating largely undetected until now"
www.silentpush.com/blog/drivesu...
Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
Silent Push observed several drive-by attack clusters using ClickFix and FakeUpdates campaigns. We named the primary driver DriveSurge.
www.silentpush.com
May 31, 2026 at 1:37 PM
-New DriveSurge group
-Infrastructure Destruction Squad fakes hacktivism to sell malware
-New ChatGPT abuse technique
-New WP malware
-Mullvad patches fingerprinting vector
-Oracle releases first monthly updates
-More Nightmare Eclipse bugs coming
-Canon fixes printer export bug
-New CIFSwitch LPE
June 1, 2026 at 7:43 AM
There's open-source traffic distribution systems now? Ha?!?

www.silentpush.com/blog/drivesu...
May 31, 2026 at 2:31 PM
A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites.
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites.
www.bleepingcomputer.com
June 1, 2026 at 10:14 PM
DriveSurge e il sistema zTDS: migliaia di siti dirottati per distribuire ClickFix e FakeUpdates su Windows e macOS
il blog: insicurezzadigitale.com/drivesurge-e...

#cybersecurity #cybercrime #cyberpedia #infosec #malware #phishing #trojan
June 4, 2026 at 7:50 AM
DriveSurge is behind a large-scale campaign hijacking thousands of legit sites via zTDS to deliver ClickFix and FakeUpdates, with added infrastructure for ad distribution and macOS payload staging. #DriveSurge #ClickFix #FakeUpdates
Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
Silent Push identified DriveSurge, a specialized Initial Access Broker using zTDS to hijack thousands of legitimate websites and redirect victims to ClickFix and FakeUpdates delivery chains at scale. The investigation also uncovered related infrastructure for ad distribution and macOS payload staging, including domains, IPs, and server fingerprints tied to DriveSurge’s broader...
www.hendryadrian.com
May 30, 2026 at 2:45 PM
New DriveSurge Threat Actor Uses ClickFix and Fake Updates to Infect Website Visitors
New DriveSurge Threat Actor Uses ClickFix and Fake Updates to Infect Website Visitors
A newly identified threat actor named DriveSurge has been quietly compromising thousands of legitimate websites to push malware onto unsuspecting visitors. Using a combination of fake browser update pages and a social engineering trick known as ClickFix, this operation ran largely undetected until now. What makes DriveSurge especially dangerous is not just its scale, but the deep sophistication built into its infrastructure to automate malware delivery at massive scale. DriveSurge works by injecting malicious code into high-reputation, legitimate websites without the knowledge of site owners or their visitors. When someone visits one of these compromised sites, hidden code quietly routes them through a Traffic Distribution System, or TDS. This system profiles each visitor and decides what to serve them next, making the attack feel natural and highly targeted at the same time. Silent Push researchers said in a report shared with Cyber Security News that they identified DriveSurge as the primary driver behind a massive surge in ClickFix and Fake Update campaigns across the web. Temporary email service provider tempmail[.]so provides long-term use services (Source – Silent Push) According to their analysis, DriveSurge operates as a specialized Initial Access Broker using a Pay-Per-Install model, where payment is collected each time a victim device is successfully infected. Those confirmed infection leads are then sold to other threat actors operating downstream. Researchers uncovered eight distinct technical fingerprints that map out DriveSurge’s malicious infrastructure, from how scripts are injected into victim sites to the registration patterns used for its domains. This level of operational detail points to a threat actor that has invested serious time into building a repeatable, scalable infection system. The group has compromised thousands of websites that redirect visitors to malware , all without site owners ever knowing. The campaign targets a wide range of browsers, including Google Chrome, Mozilla Firefox, Microsoft Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, and UC Browser. Victims encounter either a fake browser update page or a ClickFix prompt, both designed to look completely routine and trustworthy. That familiarity is exactly what makes both methods so effective against everyday users. New DriveSurge Threat Actor Uses ClickFix and Fake Updates DriveSurge deploys two main methods to trick users into installing malware on their own devices. In the Fake Update scenario, a compromised site displays a convincing browser update prompt that impersonates a well-known browser. Clicking the update button triggers the download of a ZIP file containing multiple DLL files and a “Browser Update.exe” file that is actually malware. Mozilla Firefox Update page triggered on the compromised site (Source – Silent Push) The ClickFix method works differently. A fake error message instructs the victim to copy and paste a command into their terminal or PowerShell window, which then silently installs malware. In one confirmed instance, the ClickFix prompt tried to pull malicious code from an IP address already flagged in active threat intelligence feeds. Both methods exploit the trust people naturally place in familiar websites and routine-looking browser prompts. The underlying zTDS infrastructure uses obfuscation techniques, including Base64 encoding and string manipulation, to hide malicious redirect code inside normal-looking page elements. A failover mechanism cycles through multiple backup servers to ensure the payload reaches the victim even if one delivery domain goes down. Researchers confirmed the TDS has been in active use since at least 2022. MacOS Targeting and a Cross-Platform Victim Strategy Analysis of obfuscated JavaScript files tied to DriveSurge revealed the attack chain does not only target Windows machines. One analyzed payload delivered macOS malware, showing that DriveSurge is actively building a cross-platform victim pool. The payload used a multi-stage shell command that downloaded a secondary file, executed it, and then deleted itself immediately to reduce forensic traces. Compromised site (Source – Silent Push) Researchers also discovered a separate Advertisement Distribution System linked to the campaign. This system collects device metadata and uses behavioral signals like mouse movements, scrolls, and clicks to confirm human presence before delivering content. Organizations are advised to monitor for unusual external JavaScript injections , audit third-party scripts loading from unrecognized domains, and ensure web-facing content management systems remain fully patched and access-controlled. Indicators of Compromise (IoCs):- Type Indicator Description Domain beacontrace[.]bond Malicious zTDS inject domain serving t.js script Domain jclforwarding[.]com Compromised site used to serve Fake Update / ClickFix content Domain check[.]first-node[.]rocks Malicious domain serving fake Mozilla Firefox update page Domain cptoptious[.]com zTDS delivery domain used in obfuscated payload Domain newtdsone[.]shop zTDS delivery domain used in obfuscated payload Domain captioto[.]com zTDS delivery domain used in obfuscated payload Domain banerpanel[.]live Advertisement Distribution System (ADS) panel domain Domain testio[.]ecartdev[.]com Payload and development server identified in analysis Domain ycyfugihih[.]cfd Domain linked to DriveSurge registration email pivot Domain brightson[.]icu Pre-weaponized DriveSurge infrastructure domain Domain coverlink[.]icu Pre-weaponized DriveSurge infrastructure domain Domain datumprobe[.]icu Pre-weaponized DriveSurge infrastructure domain Domain webgleam[.]info Domain identified via Fingerprint 3 infrastructure pattern Domain cptoptions[.]com Suspicious domain loaded into jclforwarding[.]com Domain banerpanel[.]live ADS domain serving casino slot machine advertisement Email thiagorivera197151[@]ycyfugihih[.]cfd DriveSurge domain registration email (Fingerprint 6 pivot) Email samuel_jordan16[@]flixtrend[.]net Second DriveSurge domain registration email (Fingerprint 7 pivot) IP Address 46[.]226[.]166[.]57 C2 server hosting macOS payload; URL: hxxp://46[.]226[.]166[.]57/ce3cbfc887?force=1 File Hash (SHA256) 90aecb370dfb1a99a1f7de0a9c6842ab1b664521fddea16b0ec9a91f322646fc ZIP file downloaded via fake Mozilla Firefox update page File Hash (SHA256) 7aa15de93cf85729ddf970e8d7897f69ece3ca29608f73e784a9ba40c9cea18d macOS payload binary retrieved from C2 server File Hash (SHA256) 29ac78c51bcdfe68c64830bdeb6e41437dd55e2691149741c9b78be03b6c82ea Malicious server body SHA256 (Fingerprint 4) File Hash (SHA256) a84b032b49773c2318b11b1164d1aada69e940229aedbf8185c33fc7dd1d2cdf Malicious server body SHA256 (Fingerprint 4 alternate) File Hash (SHA256) 428bd0b0ac36dfdd223b3953dbe61c0baf227f893310b03e7afe3111462019c6 Data hash linked to jclforwarding[.]com web resources File Name t.js Malicious injected JavaScript file (Fingerprint 1 pattern) File Name Browser Update.exe Fake browser update executable dropped via ZIP file File Name script.js Injected JavaScript file served by check[.]first-node[.]rocks File Name banner-js[.]php Script loaded into compromised sites via banerpanel[.]live File Name changelog.txt Publicly accessible file on zTDS server confirming TDS version history URL hxxps[://]newtdsone[.]shop/jsrepo?rnd= zTDS payload fetch URL embedded in obfuscated JavaScript URL hxxps[://]cptoptious[.]com/jsrepo?rnd= zTDS payload fetch URL embedded in obfuscated JavaScript URL hxxps[://]captioto[.]com/jsrepo?rnd= zTDS payload fetch URL embedded in obfuscated JavaScript URL hxxp://46[.]226[.]166[.]57/ce3cbfc887?force=1 C2 URL delivering macOS malware payload Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in Google . The post New DriveSurge Threat Actor Uses ClickFix and Fake Updates to Infect Website Visitors appeared first on Cyber Security News .
cybersecuritynews.com
June 1, 2026 at 10:33 AM
DriveSurge is using hijacked websites, ClickFix and FakeUpdate lures, and zTDS traffic routing to spread malware through fake browser update prompts, impacting Windows and macOS users. #ClickFix #FakeUpdate #DriveSurge
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
DriveSurge is running large-scale malware distribution campaigns through compromised websites using ClickFix and FakeUpdates lures, with visitors redirected by the zTDS traffic distribution system. The campaign delivers fake browser update prompts and malicious commands, affecting both Windows and macOS users while leveraging thousands of hijacked sites. #DriveSurge #SilentPush #zTDS #ClickFix #FakeUpdates
www.hendryadrian.com
June 2, 2026 at 12:45 AM
DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks
DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks
A sneaky, wide-scale IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware.
www.darkreading.com
June 2, 2026 at 8:49 PM
DriveSurgeが数千のサイトをハイジャックし、ClickFixとFakeUpdate攻撃を実行
#CybersecurityNews
www.darkreading.com/cyberattacks...
DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate
A sneaky IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware.
www.darkreading.com
June 3, 2026 at 7:15 AM
Silent Push uncovers DriveSurge as the actor behind a surge in ClickFix & FakeUpdates driveby campaigns. It seems to operate as a specialized IAB, using a pay-per-install model & thousands of compromised websites to route victims into malware delivery chains. www.silentpush.com/blog/drivesu...
June 1, 2026 at 11:06 AM
ハッカーがClickFixやFakeUpdate攻撃のために数千ものサイトを乗っ取る
#CybersecurityNews
www.bleepingcomputer.com/news/securit...
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites.
www.bleepingcomputer.com
June 3, 2026 at 7:11 AM
When trusted sites turn. [Research Saturday]

Lauren Fievisohn, Ph.D, Senior Threat Researcher from Silent Push, is sharing their work on "Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites." Silent Push researcher…
#hackernews #news
When trusted sites turn. [Research Saturday]
Lauren Fievisohn, Ph.D, Senior Threat Researcher from Silent Push, is sharing their work on "Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites." Silent Push researchers have identified a newly named threat actor, DriveSurge, which has compromised thousands of legitimate websites and uses ClickFix and fake browser update lures to distribute malware at scale through a pay-per-install operation. The group leverages a traffic distribution system called zTDS to silently redirect visitors from trusted websites to malicious payloads, while employing sophisticated infrastructure, obfuscation, and fingerprinting techniques to evade detection. The report also details how DriveSurge targets both Windows and macOS users and provides defenders with eight infrastructure fingerprints to help identify and disrupt the campaign. The research and executive brief can be found here: Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
thecyberwire.com
July 19, 2026 at 1:59 PM
Feed: "Silent Push"
By: SilentPush on Wednesday, July 15, 2026
DriveSurge actor uses ClickFix and FakeUpdates to distribute malware via compromised websites
The DriveSurge threat actor operates as an initial access broker, utilizing a pay-per-install model to facilitate subsequent attacks, according to research by SilentPush.
www.scworld.com
July 15, 2026 at 11:55 PM
Feed: "Silent Push"
By: SilentPush on Wednesday, July 15, 2026
Thousands of compromised websites abused by DriveSurge in active ClickFix and FakeUpdates campaigns
The websites are being abused as part of an Initial Access Broker campaign.
www.techradar.com
July 15, 2026 at 11:55 PM
Feed: "Silent Push"
By: SilentPush on Wednesday, July 15, 2026
DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks
A sneaky IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware.
www.darkreading.com
July 15, 2026 at 11:57 PM
DriveSurge:無数のサイトを侵害し、ClickFixと偽アップデートでドライブバイ攻撃を仕掛ける新興アクター | Codebook|Security News https://codebook.machinarecord.com/cyber-intelligence/threat-actor/46471/
July 10, 2026 at 7:55 AM
DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks: https://bit.ly/4ugfaT5 by Elizabeth Montalbano
DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate
A sneaky IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware.
bit.ly
June 2, 2026 at 9:35 PM
📰 Lanskap Ancaman Siber: Kelompok "DriveSurge" Bajak Ribuan Situs demi Kampanye ClickFix dan FakeUpdates

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/06/02/drivesurge-bajak-ribuan-situs-sebar-malware/

#bro
ws#browserUpdatek#clickfixe#drivesurgeu#fakeupdatesi#initialAccessBrokera#keama
June 2, 2026 at 3:03 AM
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks - https://bit.ly/4emNsit
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites.
bit.ly
June 4, 2026 at 6:15 PM
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks: www.bleepingcomputer.com/news/securit...
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites.
www.bleepingcomputer.com
June 1, 2026 at 11:06 PM
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites.
www.bleepingcomputer.com
June 1, 2026 at 10:57 PM