Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites

0
Medium
Published: Sat May 30 2026 (05/30/2026, 06:07:03 UTC)
Source: AlienVault OTX General

Description

DriveSurge is a newly identified threat actor operating as an Initial Access Broker that has compromised thousands of websites. The actor injects malicious code to redirect visitors through a Traffic Distribution System (zTDS) to deliver malware via FakeUpdate prompts and ClickFix PowerShell command tricks. This campaign targets multiple browsers and macOS systems, using sophisticated infrastructure such as bulletproof hosting and obfuscated JavaScript. Active since at least September 2025, DriveSurge employs unique technical fingerprints enabling detection and tracking. The threat is rated medium severity based on its widespread impact and delivery methods.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/01/2026, 10:03:30 UTC

Technical Analysis

DriveSurge operates as an Initial Access Broker using a Pay-Per-Install model, compromising thousands of websites to inject malicious code that redirects visitors through zTDS. It delivers malware primarily via two methods: FakeUpdates that impersonate browser update prompts across multiple browsers, and ClickFix, which tricks users into running malicious PowerShell commands disguised as fixes. The actor uses bulletproof hosting, obfuscated JavaScript injection, and environment-specific targeting including macOS. The campaign has been active since at least September 2025 and exhibits identifiable technical fingerprints such as unique file naming and server configurations, facilitating detection and tracking of its evolving infrastructure.

Potential Impact

The compromise of thousands of websites enables DriveSurge to redirect large volumes of web traffic to malware payloads, increasing the risk of infection for visitors. The use of FakeUpdate prompts and ClickFix PowerShell tricks can lead to execution of malicious code on victim systems, potentially resulting in system compromise. Targeting multiple browsers and macOS systems broadens the scope of affected users. As an Initial Access Broker, DriveSurge facilitates downstream attacks by supplying victim leads, amplifying the overall threat impact.

Mitigation Recommendations

No specific patch or vendor advisory is available for this threat. Mitigation should focus on detection and blocking of the injected malicious code and traffic redirection patterns associated with DriveSurge, including monitoring for FakeUpdate and ClickFix indicators. Website owners should review and secure their sites to prevent compromise, including validating third-party code and hardening web infrastructure. Users should be cautious of unsolicited update prompts and avoid executing PowerShell commands from untrusted sources. Since this is a campaign leveraging compromised sites, remediation primarily involves site owners cleaning infections and users employing endpoint protections.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.silentpush.com/blog/drivesurge/"]
Adversary
DriveSurge
Pulse Id
6a1a7e87f6f70533d1443f96
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainztds.info
domaincptoptious.com
domaincaptioto.com
domainnewtdsone.shop
domainmaxintora.com
domaincheck.first-node.rocks
domaintestio.ecartdev.com
domainwebgleam.info
domainbrightson.icu
domaindatumprobe.icu
domainkeyview.icu
domaintraceglimpse.icu
domaincoverlink.icu
domaintracekey.icu
domainbeacontrace.bond
domainbseolized.com
domaineraggifts.icu
domainjcdlforwarding.com
domainjclforwarding.com
domainycyfugihih.cfd

Ip

ValueDescriptionCopy
ip91.92.240.127
ip46.226.166.57
ip147.45.42.200
ip147.45.42.205

Hash

ValueDescriptionCopy
hash0ca424475803a1cb54908a81a00bd93f
hashf3926add1a4531ff324a6acb57d40769
hasha4f0014474278238b5fe78fc2c4182b498012a33
hash0c62c11e910d7c0d6b6c9800b70e78bfd9220e1f78bd7bb34ae4c3646d05f6e5
hash29ac78c51bcdfe68c64830bdeb6e41437dd55e2691149741c9b78be03b6c82ea
hash428bd0b0ac36dfdd223b3953dbe61c0baf227f893310b03e7afe3111462019c6
hash7aa15de93cf85729ddf970e8d7897f69ece3ca29608f73e784a9ba40c9cea18d
hash90aecb370dfb1a99a1f7de0a9c6842ab1b664521fddea16b0ec9a91f322646fc
hasha84b032b49773c2318b11b1164d1aada69e940229aedbf8185c33fc7dd1d2cdf

Url

ValueDescriptionCopy
urlhttp://bseolized.com
urlhttp://newtdsone.shop/jsrepo?rnd=

Threat ID: 6a1d5574e29bf47b50d0f56a

Added to database: 6/1/2026, 9:48:36 AM

Last enriched: 6/1/2026, 10:03:30 AM

Last updated: 6/1/2026, 2:43:38 PM

Views: 28

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses