logo

When trusted sites turn.

ID: b6470fc9-aae7-5f2f-82cb-f2b8617ed244

STIX ID: report--b6470fc9-aae7-5f2f-82cb-f2b8617ed244

Feed Name: The CyberWire

Threat Score
75/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

...
...

Silent Push researchers disclose DriveSurge, a newly named threat actor that has compromised thousands of legitimate websites to distribute malware at scale using ClickFix and fake browser-update drive-by attacks. The group leverages a traffic distribution system called zTDS to silently redirect users to malicious payloads, employs sophisticated obfuscation and fingerprinting to evade detection, targets both Windows and macOS, operates via a pay‑per‑install model, and the report includes eight infrastructure fingerprints to help defenders identify and disrupt the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.