DriveSurge Threat Actor Hijacks Thousands of Sites for ClickFix Attacks
TL;DR. A threat actor named DriveSurge uses ClickFix and FakeUpdates methods to distribute malware across thousands of compromised websites. - DriveSurge utilizes an open-source Traffic Distribution System (zTDS) to profile visitors and deliver tailored malware lures. - The attackers operate as initial access brokers, facilitating follow-on attacks through their pay-per-install model. - SilentPush researchers identified multiple technical fingerprints and numerous malicious injection domains associated with the campaign.
- DriveSurge compromises thousands of websites, redirecting visitors to malware delivery infrastructure.
- The group uses ClickFix and FakeUpdates social engineering tactics to infect systems.
- A Traffic Distribution System (zTDS) profiles victims to select appropriate lures.
- Campaign infrastructure includes over 80 malicious injection domains and pre-weaponized domains.
- macOS systems are also targeted with obfuscated JavaScript payloads through verification-themed ClickFix attacks.
Sources
- Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks — bleepingcomputer.com