logo

Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

ID: 01b15923-7496-5cd5-b11e-00e5ff9f0be7

STIX ID: report--01b15923-7496-5cd5-b11e-00e5ff9f0be7

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-01

Date Updated: 2026-06-03

Author: Bill Toulas

...
...

DriveSurge, operating as an initial access broker on a pay‑per‑install model, has compromised thousands of legitimate websites and uses the zTDS traffic distribution system to profile visitors and serve ClickFix and FakeUpdates lures that deliver malicious payloads (including Windows executables and a macOS-targeting JavaScript). Silent Push researchers identified injection patterns (t.js?site=<id>), roughly 80 malicious injection domains, pre-weaponized domains, and other technical fingerprints; users are advised to update browsers only via built-in app menus and avoid executing unknown commands.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.