DriveSurge
DriveSurge is a globally active threat cluster identified by Silent Push as the primary driver behind a surge in ClickFix and FakeUpdates campaigns. The reporting assesses DriveSurge as a specialized Initial Access Broker (IAB) operating on a pay-per-install (PPI) model, supplying downstream threat actors with victim access and confirmed infection leads. DriveSurge compromises thousands of legitimate, often high-reputation, websites by injecting malicious external JavaScript and silently redirecting real visitors to attacker-controlled infrastructure, typically without the knowledge of site owners. The actor weaponizes the open-source zTDS traffic distribution system to profile visitors and determine which lure or payload chain to serve. Reported delivery methods include FakeUpdates pages that impersonate browser updates and ClickFix lures that trick victims into copying and executing malicious commands in PowerShell or Terminal. The campaign has targeted both Windows and macOS users. Observed FakeUpdates activity includes impersonation of updates for Chrome, Firefox, Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, and UC Browser. In documented cases, victims were served a fake Firefox update that downloaded a ZIP archive containing multiple DLLs and a malicious executable named "Browser Update.exe." Observed ClickFix activity includes fake error or verification prompts, clipboard hijacking, and base64-encoded command sequences that execute malware when pasted. Researchers also observed a macOS infection chain that downloaded a secondary payload, executed it, and deleted temporary files. Silent Push reported eight technical fingerprints associated with DriveSurge infrastructure and operations, including JavaScript injection patterns such as t.js?site=<id>, SHA256-derived file naming conventions, zTDS-specific artifacts, and infrastructure patterns involving NiceNIC-registered .icu domains and shared WHOIS registration emails linked to tempmail.so. The reporting also identified more than 80 malicious injection domains, additional pre-weaponized domains, and related advertisement-distribution infrastructure. No aliases or sub-groups beyond DriveSurge were directly identified in the provided content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Observables
52 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A globally active threat cluster operating as an Initial Access Broker and using a Pay-Per-Install model to compromise legitimate websites and redirect visitors to malware delivery chains.
Initial access broker conducting large-scale malware distribution by compromising legitimate websites, redirecting visitors through the zTDS traffic distribution system, and using FakeUpdates and ClickFix lures to deliver follow-on access via a pay-per-install model.
DriveSurge is described as a specialized Initial Access Broker operating a Pay-Per-Install model. It compromises legitimate websites, injects malicious JavaScript, routes visitors through a Traffic Distribution System, and delivers malware via fake browser update pages and ClickFix social engineering. The campaign is scalable, automated, and cross-platform, including Windows and macOS targeting.
Initial access broker operating large-scale malware distribution campaigns on a pay-per-install model, compromising thousands of websites and redirecting visitors through zTDS to FakeUpdates or ClickFix lures for malware delivery.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.