A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
DriveSurge is a newly identified threat actor operating as an Initial Access Broker that has compromised thousands of websites. The actor injects malicious code to redirect visitors through a Traffic Distribution System (zTDS) to deliver malware via FakeUpdate prompts and ClickFix PowerShell command tricks. This campaign targets multiple browsers and macOS systems, using sophisticated infrastructure such as bulletproof hosting and obfuscated JavaScript. Active since at least September 2025, DriveSurge employs unique technical fingerprints enabling detection and tracking. The threat is rated medium severity based on its widespread impact and delivery methods.
AI Analysis
Technical Summary
DriveSurge operates as an Initial Access Broker using a Pay-Per-Install model, compromising thousands of websites to inject malicious code that redirects visitors through zTDS. It delivers malware primarily via two methods: FakeUpdates that impersonate browser update prompts across multiple browsers, and ClickFix, which tricks users into running malicious PowerShell commands disguised as fixes. The actor uses bulletproof hosting, obfuscated JavaScript injection, and environment-specific targeting including macOS. The campaign has been active since at least September 2025 and exhibits identifiable technical fingerprints such as unique file naming and server configurations, facilitating detection and tracking of its evolving infrastructure.
Potential Impact
The compromise of thousands of websites enables DriveSurge to redirect large volumes of web traffic to malware payloads, increasing the risk of infection for visitors. The use of FakeUpdate prompts and ClickFix PowerShell tricks can lead to execution of malicious code on victim systems, potentially resulting in system compromise. Targeting multiple browsers and macOS systems broadens the scope of affected users. As an Initial Access Broker, DriveSurge facilitates downstream attacks by supplying victim leads, amplifying the overall threat impact.
Mitigation Recommendations
No specific patch or vendor advisory is available for this threat. Mitigation should focus on detection and blocking of the injected malicious code and traffic redirection patterns associated with DriveSurge, including monitoring for FakeUpdate and ClickFix indicators. Website owners should review and secure their sites to prevent compromise, including validating third-party code and hardening web infrastructure. Users should be cautious of unsolicited update prompts and avoid executing PowerShell commands from untrusted sources. Since this is a campaign leveraging compromised sites, remediation primarily involves site owners cleaning infections and users employing endpoint protections.
Indicators of Compromise
- domain: ztds.info
- ip: 91.92.240.127
- ip: 46.226.166.57
- domain: cptoptious.com
- domain: captioto.com
- domain: newtdsone.shop
- domain: maxintora.com
- domain: check.first-node.rocks
- domain: testio.ecartdev.com
- domain: webgleam.info
- domain: brightson.icu
- domain: datumprobe.icu
- domain: keyview.icu
- domain: traceglimpse.icu
- domain: coverlink.icu
- domain: tracekey.icu
- hash: 0ca424475803a1cb54908a81a00bd93f
- hash: f3926add1a4531ff324a6acb57d40769
- hash: a4f0014474278238b5fe78fc2c4182b498012a33
- hash: 0c62c11e910d7c0d6b6c9800b70e78bfd9220e1f78bd7bb34ae4c3646d05f6e5
- hash: 29ac78c51bcdfe68c64830bdeb6e41437dd55e2691149741c9b78be03b6c82ea
- hash: 428bd0b0ac36dfdd223b3953dbe61c0baf227f893310b03e7afe3111462019c6
- hash: 7aa15de93cf85729ddf970e8d7897f69ece3ca29608f73e784a9ba40c9cea18d
- hash: 90aecb370dfb1a99a1f7de0a9c6842ab1b664521fddea16b0ec9a91f322646fc
- hash: a84b032b49773c2318b11b1164d1aada69e940229aedbf8185c33fc7dd1d2cdf
- ip: 147.45.42.200
- ip: 147.45.42.205
- url: http://bseolized.com
- url: http://newtdsone.shop/jsrepo?rnd=
- domain: beacontrace.bond
- domain: bseolized.com
- domain: eraggifts.icu
- domain: jcdlforwarding.com
- domain: jclforwarding.com
- domain: ycyfugihih.cfd
A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
Description
DriveSurge is a newly identified threat actor operating as an Initial Access Broker that has compromised thousands of websites. The actor injects malicious code to redirect visitors through a Traffic Distribution System (zTDS) to deliver malware via FakeUpdate prompts and ClickFix PowerShell command tricks. This campaign targets multiple browsers and macOS systems, using sophisticated infrastructure such as bulletproof hosting and obfuscated JavaScript. Active since at least September 2025, DriveSurge employs unique technical fingerprints enabling detection and tracking. The threat is rated medium severity based on its widespread impact and delivery methods.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
DriveSurge operates as an Initial Access Broker using a Pay-Per-Install model, compromising thousands of websites to inject malicious code that redirects visitors through zTDS. It delivers malware primarily via two methods: FakeUpdates that impersonate browser update prompts across multiple browsers, and ClickFix, which tricks users into running malicious PowerShell commands disguised as fixes. The actor uses bulletproof hosting, obfuscated JavaScript injection, and environment-specific targeting including macOS. The campaign has been active since at least September 2025 and exhibits identifiable technical fingerprints such as unique file naming and server configurations, facilitating detection and tracking of its evolving infrastructure.
Potential Impact
The compromise of thousands of websites enables DriveSurge to redirect large volumes of web traffic to malware payloads, increasing the risk of infection for visitors. The use of FakeUpdate prompts and ClickFix PowerShell tricks can lead to execution of malicious code on victim systems, potentially resulting in system compromise. Targeting multiple browsers and macOS systems broadens the scope of affected users. As an Initial Access Broker, DriveSurge facilitates downstream attacks by supplying victim leads, amplifying the overall threat impact.
Mitigation Recommendations
No specific patch or vendor advisory is available for this threat. Mitigation should focus on detection and blocking of the injected malicious code and traffic redirection patterns associated with DriveSurge, including monitoring for FakeUpdate and ClickFix indicators. Website owners should review and secure their sites to prevent compromise, including validating third-party code and hardening web infrastructure. Users should be cautious of unsolicited update prompts and avoid executing PowerShell commands from untrusted sources. Since this is a campaign leveraging compromised sites, remediation primarily involves site owners cleaning infections and users employing endpoint protections.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.silentpush.com/blog/drivesurge/"]
- Adversary
- DriveSurge
- Pulse Id
- 6a1a7e87f6f70533d1443f96
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainztds.info | — | |
domaincptoptious.com | — | |
domaincaptioto.com | — | |
domainnewtdsone.shop | — | |
domainmaxintora.com | — | |
domaincheck.first-node.rocks | — | |
domaintestio.ecartdev.com | — | |
domainwebgleam.info | — | |
domainbrightson.icu | — | |
domaindatumprobe.icu | — | |
domainkeyview.icu | — | |
domaintraceglimpse.icu | — | |
domaincoverlink.icu | — | |
domaintracekey.icu | — | |
domainbeacontrace.bond | — | |
domainbseolized.com | — | |
domaineraggifts.icu | — | |
domainjcdlforwarding.com | — | |
domainjclforwarding.com | — | |
domainycyfugihih.cfd | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip91.92.240.127 | — | |
ip46.226.166.57 | — | |
ip147.45.42.200 | — | |
ip147.45.42.205 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash0ca424475803a1cb54908a81a00bd93f | — | |
hashf3926add1a4531ff324a6acb57d40769 | — | |
hasha4f0014474278238b5fe78fc2c4182b498012a33 | — | |
hash0c62c11e910d7c0d6b6c9800b70e78bfd9220e1f78bd7bb34ae4c3646d05f6e5 | — | |
hash29ac78c51bcdfe68c64830bdeb6e41437dd55e2691149741c9b78be03b6c82ea | — | |
hash428bd0b0ac36dfdd223b3953dbe61c0baf227f893310b03e7afe3111462019c6 | — | |
hash7aa15de93cf85729ddf970e8d7897f69ece3ca29608f73e784a9ba40c9cea18d | — | |
hash90aecb370dfb1a99a1f7de0a9c6842ab1b664521fddea16b0ec9a91f322646fc | — | |
hasha84b032b49773c2318b11b1164d1aada69e940229aedbf8185c33fc7dd1d2cdf | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://bseolized.com | — | |
urlhttp://newtdsone.shop/jsrepo?rnd= | — |
Threat ID: 6a1d5574e29bf47b50d0f56a
Added to database: 6/1/2026, 9:48:36 AM
Last enriched: 6/1/2026, 10:03:30 AM
Last updated: 6/1/2026, 2:43:38 PM
Views: 28
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.