Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites

0
Medium
Published: 05/30/2026 (05/30/2026, 06:07:03 UTC)
Source: AlienVault OTX General

Description

DriveSurge is a newly identified threat actor operating as an Initial Access Broker using a Pay-Per-Install model to supply victim leads to downstream actors. The actor has compromised thousands of websites, injecting malicious code that redirects visitors through zTDS (Traffic Distribution System) to deliver malware via two primary methods: FakeUpdates, which impersonate browser update prompts for Chrome, Firefox, Edge, Safari, and eight other browsers; and ClickFix, which tricks users into executing malicious PowerShell commands disguised as fixes. DriveSurge leverages sophisticated infrastructure including bulletproof hosting, obfuscated JavaScript injection patterns, and environment-specific targeting including macOS systems. The operation has been active since at least September 2025, utilizing specific technical fingerprints including unique file naming conventions and server configurations that enable detection and tracking of their evolving infrastructure.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/01/2026, 20:52:04 UTC

Technical Analysis

DriveSurge is an Initial Access Broker threat actor that compromises thousands of websites to inject malicious code redirecting visitors through a Traffic Distribution System (zTDS). It delivers malware primarily via two methods: FakeUpdates, which mimic browser update prompts for Chrome, Firefox, Edge, Safari, and others, and ClickFix, which deceives users into executing malicious PowerShell commands disguised as fixes. The actor leverages bulletproof hosting, obfuscated JavaScript injection patterns, and environment-specific targeting including macOS systems. This campaign has been active since at least September 2025 and uses identifiable technical fingerprints such as unique file naming conventions and server configurations to facilitate detection and tracking.

Potential Impact

The compromise of thousands of websites enables DriveSurge to redirect large volumes of web traffic to malicious payloads, increasing the risk of malware infections for visitors. The use of FakeUpdates and ClickFix techniques can lead to execution of malicious code on victim systems, potentially resulting in system compromise, data theft, or further malware deployment. Targeting multiple browsers and macOS environments broadens the scope of affected users. As an Initial Access Broker, DriveSurge facilitates downstream attacks by supplying victim leads, amplifying the overall threat impact.

Mitigation Recommendations

No official patch or fix is available as this is a threat actor campaign rather than a software vulnerability. Mitigation focuses on detection and prevention of malicious code injections on websites, monitoring for indicators of compromise related to DriveSurge’s unique fingerprints, and educating users to recognize and avoid FakeUpdate prompts and suspicious PowerShell execution requests. Website administrators should review and secure their sites against unauthorized code injections. Users should avoid interacting with unexpected browser update prompts and refrain from executing unsolicited PowerShell commands. Since this is not a cloud service, remediation depends on affected site operators.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.silentpush.com/blog/drivesurge/"]
Adversary
DriveSurge
Pulse Id
6a1a7e87f6f70533d1443f96
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domainztds.info
domaincptoptious.com
domaincaptioto.com
domainnewtdsone.shop
domainmaxintora.com
domaincheck.first-node.rocks
domaintestio.ecartdev.com
domainwebgleam.info
domainbrightson.icu
domaindatumprobe.icu
domainkeyview.icu
domaintraceglimpse.icu
domaincoverlink.icu
domaintracekey.icu
domainbeacontrace.bond
domainbseolized.com
domaineraggifts.icu
domainjcdlforwarding.com
domainjclforwarding.com
domainycyfugihih.cfd

Ip

ValueDescriptionCopy
ip91.92.240.127
ip46.226.166.57
ip147.45.42.200
ip147.45.42.205

Hash

ValueDescriptionCopy
hash0ca424475803a1cb54908a81a00bd93f
hashf3926add1a4531ff324a6acb57d40769
hasha4f0014474278238b5fe78fc2c4182b498012a33
hash0c62c11e910d7c0d6b6c9800b70e78bfd9220e1f78bd7bb34ae4c3646d05f6e5
hash29ac78c51bcdfe68c64830bdeb6e41437dd55e2691149741c9b78be03b6c82ea
hash428bd0b0ac36dfdd223b3953dbe61c0baf227f893310b03e7afe3111462019c6
hash7aa15de93cf85729ddf970e8d7897f69ece3ca29608f73e784a9ba40c9cea18d
hash90aecb370dfb1a99a1f7de0a9c6842ab1b664521fddea16b0ec9a91f322646fc
hasha84b032b49773c2318b11b1164d1aada69e940229aedbf8185c33fc7dd1d2cdf

Url

ValueDescriptionCopy
urlhttp://bseolized.com
urlhttp://newtdsone.shop/jsrepo?rnd=

Threat ID: 6a1d5574e29bf47b50d0f56a

Added to database: 06/01/2026, 09:48:36 UTC

Last enriched: 07/01/2026, 20:52:04 UTC

Last updated: 07/30/2026, 06:50:42 UTC

Views: 201

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses