A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
A sophisticated threat actor named DriveSurge operates as an Initial Access Broker using a Pay-Per-Install model to deliver malware at scale. The actor compromises thousands of legitimate websites and uses zTDS (Traffic Distribution System) to silently redirect visitors to malicious content. Victims encounter either FakeUpdates campaigns that impersonate browser update prompts for 11 different browsers, or ClickFix attacks that trick users into executing malicious commands through fake error messages. DriveSurge's infrastructure utilizes bulletproof hosting services, primarily NiceNIC registrar, and has been operating since at least 2015. The campaigns target both Windows and macOS systems, employing sophisticated obfuscation techniques and clipboard hijacking to achieve infection. Eight technical fingerprints have been identified to track this actor's infrastructure and activities.
Pulse ID: 6a1dde5fb26dd1b1cbbdb913
Pulse Link: https://otx.alienvault.com/pulse/6a1dde5fb26dd1b1cbbdb913
Pulse Author: AlienVault
Created: 2026-06-01 19:32:47
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Clipboard #CyberSecurity #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #Windows #bot #AlienVault










