Researchers identified DriveSurge as a large-scale threat actor operating as an apparent initial access broker, compromising legitimate websites and redirecting visitors into ClickFix and fake browser update infection chains. The operation uses the open-source zTDS traffic distribution system to profile victims, selectively route traffic, and deliver malware across Windows and macOS environments. Investigators linked the campaign to thousands of compromised sites, NiceNIC-registered domains, Russian-linked infrastructure patterns, multiple payload servers, and a command-and-control endpoint, indicating a mature pay-per-install ecosystem built to provide downstream actors with scalable victim access.
Silent Push said it developed eight infrastructure fingerprints spanning malicious JavaScript injections, server configurations, WHOIS pivots, and zTDS artifacts to map both active and pre-weaponized infrastructure. The campaign has reportedly been active since at least 2022, using obfuscation, failover delivery paths, ZIP-based fake updates, and terminal- or PowerShell-driven ClickFix lures to infect users across major browsers. Researchers urged defenders to hunt for unauthorized JavaScript on web properties, scrutinize third-party scripts from unknown domains, and harden internet-facing CMS platforms through patching and tighter access controls.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A report described RedSun, tracked as CVE-2026-41091, as a local privilege escalation vulnerability in Microsoft Windows Defender's remediation workflow discovered by Nightmare Eclipse. The disclosure detailed how Cloud Files placeholders, NTFS junctions, Volume Shadow Copy detection, and oplocks could be combined to achieve arbitrary file writes into System32 and execute code as SYSTEM.
Silent Push reported that the infrastructure associated with the newly named DriveSurge threat actor has been active since at least 2022. The operation uses compromised websites and the zTDS traffic distribution system to redirect visitors into FakeUpdates and ClickFix malware delivery chains.
Silent Push disclosed a large-scale malware delivery operation it named DriveSurge, describing it as a specialized initial access broker using a pay-per-install model. The report linked the actor to thousands of compromised websites, zTDS-based redirection, malicious domains, payload infrastructure, and macOS as well as Windows malware delivery.
Avast Decoded published research on Lazarus and the FudModule rootkit, describing advanced exploits that went beyond bring-your-own-vulnerable-driver techniques and included an admin-to-kernel zero-day. This marks a public technical disclosure of the activity and tooling discussed in the report.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcedarkreading.com
Open sourcemalware.news
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcesilentpush.com
Open sourcedecoded.avast.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.