DriveSurge Threat Cluster Exploits Thousands of Websites Globally
ID: 1b4d36a5-8222-50ff-8cb3-0ea1c9681adb
STIX ID: report--1b4d36a5-8222-50ff-8cb3-0ea1c9681adb
Feed Name: securityonline.info
Threat Score
DriveSurge is a global, profit-driven initial access campaign that leverages the open-source zTDS traffic distribution system to compromise thousands of legitimate websites and deliver malware via convincing FakeUpdate prompts and clipboard-hijacking ClickFix prompts; analysts have identified injection fingerprints, domain registration patterns (.icu via NiceNIC and tempmail.so contact), and remediation steps for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
