DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks
A sophisticated cybercriminal operation, dubbed DriveSurge, has been hijacking thousands of legitimate websites to distribute malware, primarily through ClickFix and FakeUpdate attacks. The operation utilizes a traffic distribution system (TDS) based on zTDS to redirect users to malicious payloads, targeting Windows and macOS systems. This activity highlights a mature, long-term cybercriminal ecosystem focused on providing initial access to victims for a fee, demonstrating a significant scale and level of sophistication.
DriveSurge is a wide-scale operation leveraging a traffic distribution system (TDS) to redirect visitors from trusted websites to those delivering malware. The core of the operation involves compromised websites utilizing zTDS, a publicly available open-source tool, to serve malicious content. This allows threat actors to bypass typical security measures and deliver payloads directly to unsuspecting users. The campaign’s scale, spanning thousands of websites, and its use of obfuscated JavaScript and multiple fallback domains demonstrate a significant investment in resilience and evasion techniques. The operation’s unique business model, selling initial access to systems via a pay-per-install (PPI) model, adds a layer of complexity and sophistication, transforming the activity into a legitimate cybercrime service. The campaign has been active since at least September 2025, remaining largely undetected until February 2026, showcasing the attackers' ability to maintain operational security.
