A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
DriveSurge is a newly identified threat actor operating as an Initial Access Broker using a Pay-Per-Install model to supply victim leads to downstream actors. The actor has compromised thousands of websites, injecting malicious code that redirects visitors through zTDS (Traffic Distribution System) to deliver malware via two primary methods: FakeUpdates, which impersonate browser update prompts for Chrome, Firefox, Edge, Safari, and eight other browsers; and ClickFix, which tricks users into executing malicious PowerShell commands disguised as fixes. DriveSurge leverages sophisticated infrastructure including bulletproof hosting, obfuscated JavaScript injection patterns, and environment-specific targeting including macOS systems. The operation has been active since at least September 2025, utilizing specific technical fingerprints including unique file naming conventions and server configurations that enable detection and tracking of their evolving infrastructure.
AI Analysis
Technical Summary
DriveSurge is an Initial Access Broker threat actor that compromises thousands of websites to inject malicious code redirecting visitors through a Traffic Distribution System (zTDS). It delivers malware primarily via two methods: FakeUpdates, which mimic browser update prompts for Chrome, Firefox, Edge, Safari, and others, and ClickFix, which deceives users into executing malicious PowerShell commands disguised as fixes. The actor leverages bulletproof hosting, obfuscated JavaScript injection patterns, and environment-specific targeting including macOS systems. This campaign has been active since at least September 2025 and uses identifiable technical fingerprints such as unique file naming conventions and server configurations to facilitate detection and tracking.
Potential Impact
The compromise of thousands of websites enables DriveSurge to redirect large volumes of web traffic to malicious payloads, increasing the risk of malware infections for visitors. The use of FakeUpdates and ClickFix techniques can lead to execution of malicious code on victim systems, potentially resulting in system compromise, data theft, or further malware deployment. Targeting multiple browsers and macOS environments broadens the scope of affected users. As an Initial Access Broker, DriveSurge facilitates downstream attacks by supplying victim leads, amplifying the overall threat impact.
Mitigation Recommendations
No official patch or fix is available as this is a threat actor campaign rather than a software vulnerability. Mitigation focuses on detection and prevention of malicious code injections on websites, monitoring for indicators of compromise related to DriveSurge’s unique fingerprints, and educating users to recognize and avoid FakeUpdate prompts and suspicious PowerShell execution requests. Website administrators should review and secure their sites against unauthorized code injections. Users should avoid interacting with unexpected browser update prompts and refrain from executing unsolicited PowerShell commands. Since this is not a cloud service, remediation depends on affected site operators.
Indicators of Compromise
- domain: ztds.info
- ip: 91.92.240.127
- ip: 46.226.166.57
- domain: cptoptious.com
- domain: captioto.com
- domain: newtdsone.shop
- domain: maxintora.com
- domain: check.first-node.rocks
- domain: testio.ecartdev.com
- domain: webgleam.info
- domain: brightson.icu
- domain: datumprobe.icu
- domain: keyview.icu
- domain: traceglimpse.icu
- domain: coverlink.icu
- domain: tracekey.icu
- hash: 0ca424475803a1cb54908a81a00bd93f
- hash: f3926add1a4531ff324a6acb57d40769
- hash: a4f0014474278238b5fe78fc2c4182b498012a33
- hash: 0c62c11e910d7c0d6b6c9800b70e78bfd9220e1f78bd7bb34ae4c3646d05f6e5
- hash: 29ac78c51bcdfe68c64830bdeb6e41437dd55e2691149741c9b78be03b6c82ea
- hash: 428bd0b0ac36dfdd223b3953dbe61c0baf227f893310b03e7afe3111462019c6
- hash: 7aa15de93cf85729ddf970e8d7897f69ece3ca29608f73e784a9ba40c9cea18d
- hash: 90aecb370dfb1a99a1f7de0a9c6842ab1b664521fddea16b0ec9a91f322646fc
- hash: a84b032b49773c2318b11b1164d1aada69e940229aedbf8185c33fc7dd1d2cdf
- ip: 147.45.42.200
- ip: 147.45.42.205
- url: http://bseolized.com
- url: http://newtdsone.shop/jsrepo?rnd=
- domain: beacontrace.bond
- domain: bseolized.com
- domain: eraggifts.icu
- domain: jcdlforwarding.com
- domain: jclforwarding.com
- domain: ycyfugihih.cfd
A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
Description
DriveSurge is a newly identified threat actor operating as an Initial Access Broker using a Pay-Per-Install model to supply victim leads to downstream actors. The actor has compromised thousands of websites, injecting malicious code that redirects visitors through zTDS (Traffic Distribution System) to deliver malware via two primary methods: FakeUpdates, which impersonate browser update prompts for Chrome, Firefox, Edge, Safari, and eight other browsers; and ClickFix, which tricks users into executing malicious PowerShell commands disguised as fixes. DriveSurge leverages sophisticated infrastructure including bulletproof hosting, obfuscated JavaScript injection patterns, and environment-specific targeting including macOS systems. The operation has been active since at least September 2025, utilizing specific technical fingerprints including unique file naming conventions and server configurations that enable detection and tracking of their evolving infrastructure.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
DriveSurge is an Initial Access Broker threat actor that compromises thousands of websites to inject malicious code redirecting visitors through a Traffic Distribution System (zTDS). It delivers malware primarily via two methods: FakeUpdates, which mimic browser update prompts for Chrome, Firefox, Edge, Safari, and others, and ClickFix, which deceives users into executing malicious PowerShell commands disguised as fixes. The actor leverages bulletproof hosting, obfuscated JavaScript injection patterns, and environment-specific targeting including macOS systems. This campaign has been active since at least September 2025 and uses identifiable technical fingerprints such as unique file naming conventions and server configurations to facilitate detection and tracking.
Potential Impact
The compromise of thousands of websites enables DriveSurge to redirect large volumes of web traffic to malicious payloads, increasing the risk of malware infections for visitors. The use of FakeUpdates and ClickFix techniques can lead to execution of malicious code on victim systems, potentially resulting in system compromise, data theft, or further malware deployment. Targeting multiple browsers and macOS environments broadens the scope of affected users. As an Initial Access Broker, DriveSurge facilitates downstream attacks by supplying victim leads, amplifying the overall threat impact.
Mitigation Recommendations
No official patch or fix is available as this is a threat actor campaign rather than a software vulnerability. Mitigation focuses on detection and prevention of malicious code injections on websites, monitoring for indicators of compromise related to DriveSurge’s unique fingerprints, and educating users to recognize and avoid FakeUpdate prompts and suspicious PowerShell execution requests. Website administrators should review and secure their sites against unauthorized code injections. Users should avoid interacting with unexpected browser update prompts and refrain from executing unsolicited PowerShell commands. Since this is not a cloud service, remediation depends on affected site operators.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.silentpush.com/blog/drivesurge/"]
- Adversary
- DriveSurge
- Pulse Id
- 6a1a7e87f6f70533d1443f96
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainztds.info | — | |
domaincptoptious.com | — | |
domaincaptioto.com | — | |
domainnewtdsone.shop | — | |
domainmaxintora.com | — | |
domaincheck.first-node.rocks | — | |
domaintestio.ecartdev.com | — | |
domainwebgleam.info | — | |
domainbrightson.icu | — | |
domaindatumprobe.icu | — | |
domainkeyview.icu | — | |
domaintraceglimpse.icu | — | |
domaincoverlink.icu | — | |
domaintracekey.icu | — | |
domainbeacontrace.bond | — | |
domainbseolized.com | — | |
domaineraggifts.icu | — | |
domainjcdlforwarding.com | — | |
domainjclforwarding.com | — | |
domainycyfugihih.cfd | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip91.92.240.127 | — | |
ip46.226.166.57 | — | |
ip147.45.42.200 | — | |
ip147.45.42.205 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash0ca424475803a1cb54908a81a00bd93f | — | |
hashf3926add1a4531ff324a6acb57d40769 | — | |
hasha4f0014474278238b5fe78fc2c4182b498012a33 | — | |
hash0c62c11e910d7c0d6b6c9800b70e78bfd9220e1f78bd7bb34ae4c3646d05f6e5 | — | |
hash29ac78c51bcdfe68c64830bdeb6e41437dd55e2691149741c9b78be03b6c82ea | — | |
hash428bd0b0ac36dfdd223b3953dbe61c0baf227f893310b03e7afe3111462019c6 | — | |
hash7aa15de93cf85729ddf970e8d7897f69ece3ca29608f73e784a9ba40c9cea18d | — | |
hash90aecb370dfb1a99a1f7de0a9c6842ab1b664521fddea16b0ec9a91f322646fc | — | |
hasha84b032b49773c2318b11b1164d1aada69e940229aedbf8185c33fc7dd1d2cdf | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://bseolized.com | — | |
urlhttp://newtdsone.shop/jsrepo?rnd= | — |
Threat ID: 6a1d5574e29bf47b50d0f56a
Added to database: 06/01/2026, 09:48:36 UTC
Last enriched: 07/01/2026, 20:52:04 UTC
Last updated: 07/30/2026, 06:50:42 UTC
Views: 201
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.