Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

0
Medium
Malware
Published: Mon Jun 01 2026 (06/01/2026, 22:14:19 UTC)
Source: Bleeping Computer

Description

The DriveSurge threat actor has compromised thousands of legitimate websites to conduct large-scale malware distribution campaigns using ClickFix and FakeUpdates social engineering techniques. Visitors to these sites are redirected via a Traffic Distribution System (zTDS) to tailored malware lures, including fake browser update prompts and malicious PowerShell commands. The campaign targets multiple browsers and platforms, including Windows and macOS. DriveSurge operates as an initial access broker on a pay-per-install model, facilitating further attacks. Users are advised to only update browsers via official settings and avoid executing unknown commands.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/01/2026, 22:18:43 UTC

Technical Analysis

DriveSurge is a threat actor conducting widespread malware distribution by compromising thousands of high-reputation websites. Using the open-source Traffic Distribution System zTDS, visitors are profiled and redirected to either ClickFix or FakeUpdates social engineering attacks. ClickFix tricks victims into running malicious PowerShell commands, while FakeUpdates present fraudulent browser update prompts to deliver malware payloads. The campaign targets multiple browsers (Chrome, Firefox, Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, UC Browser) and platforms, including macOS via clipboard hijacking. DriveSurge functions as an initial access broker operating on a pay-per-install basis, enabling follow-on attacks. Researchers identified multiple technical fingerprints and injection domains linked to this campaign.

Potential Impact

The campaign results in malware infections on victim systems through social engineering, potentially leading to further compromise facilitated by DriveSurge's pay-per-install model. Legitimate websites are hijacked without owners' knowledge, exposing their visitors to malicious redirects and payloads. The threat affects multiple browsers and operating systems, increasing its reach. There is no indication of direct exploitation of software vulnerabilities; the attack relies on deception and compromised infrastructure.

Mitigation Recommendations

No official patch or vendor advisory is available for this threat. Users should only download browser updates through the official application settings menu (About > Check for Updates) and avoid executing commands in command prompts or terminals unless fully understood. Website owners should investigate and remediate unauthorized JavaScript injections, specifically those matching the 't.js?site=<id>' pattern, and monitor for signs of compromise. Since this is a malware distribution campaign leveraging compromised sites, remediation involves cleaning affected websites and improving security to prevent reinfection.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/hackers-hijack-thousands-of-sites-for-clickfix-and-fakeupdate-attacks/","fetched":true,"fetchedAt":"2026-06-01T22:18:36.183Z","wordCount":753}

Threat ID: 6a1e053ce29bf47b504fa458

Added to database: 6/1/2026, 10:18:36 PM

Last enriched: 6/1/2026, 10:18:43 PM

Last updated: 6/2/2026, 6:50:53 AM

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses