DriveSurge Threat Actor Hijacks Thousands of Sites for ClickFix Attacks

TL;DR. A threat actor named DriveSurge uses ClickFix and FakeUpdates methods to distribute malware across thousands of compromised websites. - DriveSurge utilizes an open-source Traffic Distribution System (zTDS) to profile visitors and deliver tailored malware lures. - The attackers operate as initial access brokers, facilitating follow-on attacks through their pay-per-install model. - SilentPush researchers identified multiple technical fingerprints and numerous malicious injection domains associated with the campaign.

Sources

Back to QLANKR News