logo

DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks

ID: 65d69b0d-7bcd-5dab-8373-48b4b53b12bc

STIX ID: report--65d69b0d-7bcd-5dab-8373-48b4b53b12bc

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2026-06-02

Date Updated: 2026-06-15

Author: Elizabeth Montalbano

...
...

Researchers discovered DriveSurge, an industrialized initial-access-for-hire operation that hijacks thousands of legitimate websites using the open-source zTDS traffic distribution system to route victims to FakeUpdate and ClickFix payloads (targeting Windows and macOS). The campaign uses obfuscated JavaScript, platform profiling, payload repositories, fallback domains, and pay-per-install mechanisms to sell high-quality access; defenders are advised to block malicious domains, monitor for suspicious outbound traffic and injected JavaScript, and train users not to paste commands or install updates from non-vendor sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.