Skip to main content
Mallory

DriveSurge

Also known asdrivesurge

DriveSurge is a globally active threat cluster identified by Silent Push as the primary driver behind a surge in ClickFix and FakeUpdates campaigns. The reporting assesses DriveSurge as a specialized Initial Access Broker (IAB) operating on a pay-per-install (PPI) model, supplying downstream threat actors with victim access and confirmed infection leads. DriveSurge compromises thousands of legitimate, often high-reputation, websites by injecting malicious external JavaScript and silently redirecting real visitors to attacker-controlled infrastructure, typically without the knowledge of site owners. The actor weaponizes the open-source zTDS traffic distribution system to profile visitors and determine which lure or payload chain to serve. Reported delivery methods include FakeUpdates pages that impersonate browser updates and ClickFix lures that trick victims into copying and executing malicious commands in PowerShell or Terminal. The campaign has targeted both Windows and macOS users. Observed FakeUpdates activity includes impersonation of updates for Chrome, Firefox, Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, and UC Browser. In documented cases, victims were served a fake Firefox update that downloaded a ZIP archive containing multiple DLLs and a malicious executable named "Browser Update.exe." Observed ClickFix activity includes fake error or verification prompts, clipboard hijacking, and base64-encoded command sequences that execute malware when pasted. Researchers also observed a macOS infection chain that downloaded a secondary payload, executed it, and deleted temporary files. Silent Push reported eight technical fingerprints associated with DriveSurge infrastructure and operations, including JavaScript injection patterns such as t.js?site=<id>, SHA256-derived file naming conventions, zTDS-specific artifacts, and infrastructure patterns involving NiceNIC-registered .icu domains and shared WHOIS registration emails linked to tempmail.so. The reporting also identified more than 80 malicious injection domains, additional pre-weaponized domains, and related advertisement-distribution infrastructure. No aliases or sub-groups beyond DriveSurge were directly identified in the provided content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

7 of 15 tactics25 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.001
Domains
TA0001
Initial Access
2 techniques
T1189×6
Drive-by Compromise
T1566
Phishing
T1566.002×2
Spearphishing Link
TA0002
Execution
2 techniques
T1059×2
Command and Scripting Interpreter
T1059.001×6
PowerShell
T1059.004×2
Unix Shell
T1059.007×5
JavaScript
T1204×5
User Execution
T1204.002×3
Malicious File
T1204.003
Malicious Image
TA0005
Stealth
3 techniques
T1027×4
Obfuscated Files or Information
T1070
Indicator Removal
T1070.004
File Deletion
T1497
Virtualization/Sandbox Evasion
T1497.001×2
System Checks
TA0007
Discovery
2 techniques
T1082
System Information Discovery
T1497
Virtualization/Sandbox Evasion
T1497.001×2
System Checks
TA0009
Collection
2 techniques
T1115×4
Clipboard Data
T1560
Archive Collected Data
TA0011
Command and Control
3 techniques
T1008
Fallback Channels
T1071
Application Layer Protocol
T1105×4
Ingress Tool Transfer
IOCS

Observables

52 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

security online infoNews
Jun 4, 2026
DriveSurge Threat Cluster: Traffic Distribution System Alert

A globally active threat cluster operating as an Initial Access Broker and using a Pay-Per-Install model to compromise legitimate websites and redirect visitors to malware delivery chains.

Read more
scworldNews
Jun 2, 2026
DriveSurge actor uses ClickFix and FakeUpdates to distribute malware via compromised websites | brief | SC Media

Initial access broker conducting large-scale malware distribution by compromising legitimate websites, redirecting visitors through the zTDS traffic distribution system, and using FakeUpdates and ClickFix lures to deliver follow-on access via a pay-per-install model.

Read more
cyber security newsNews
Jun 1, 2026
New DriveSurge Threat Actor Uses ClickFix and Fake Updates to Infect Website Visitors

DriveSurge is described as a specialized Initial Access Broker operating a Pay-Per-Install model. It compromises legitimate websites, injects malicious JavaScript, routes visitors through a Traffic Distribution System, and delivers malware via fake browser update pages and ClickFix social engineering. The campaign is scalable, automated, and cross-platform, including Windows and macOS targeting.

Read more
bleeping computerNews
Jun 1, 2026
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

Initial access broker operating large-scale malware distribution campaigns on a pay-per-install model, compromising thousands of websites and redirecting visitors through zTDS to FakeUpdates or ClickFix lures for malware delivery.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping19

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables52

Domains, IPs, and hashes tied to this actor, refreshed continuously.