When trusted sites turn.
ID: b6470fc9-aae7-5f2f-82cb-f2b8617ed244
STIX ID: report--b6470fc9-aae7-5f2f-82cb-f2b8617ed244
Feed Name: The CyberWire
Silent Push researchers disclose DriveSurge, a newly named threat actor that has compromised thousands of legitimate websites to distribute malware at scale using ClickFix and fake browser-update drive-by attacks. The group leverages a traffic distribution system called zTDS to silently redirect users to malicious payloads, employs sophisticated obfuscation and fingerprinting to evade detection, targets both Windows and macOS, operates via a pay‑per‑install model, and the report includes eight infrastructure fingerprints to help defenders identify and disrupt the campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
