Multiple reports describe an ongoing campaign attributed to an “initial access broker” (IAB) actor called DriveSurge that compromises or abuses large numbers of websites to redirect visitors to attacker-controlled content. According to the reporting, DriveSurge uses a malicious traffic distribution system (TDS) to hijack the normal flow from trusted sites, sending users to pages that deliver malware or attacker infrastructure. The campaign is associated with two techniques: “ClickFix,” which alters or influences user interactions to drive victims toward malicious outcomes, and “FakeUpdate” attacks, which present counterfeit software or update prompts to trick users into installing or enabling malicious payloads. Bleeping Computer and Dark Reading both describe the campaign as affecting thousands of sites and functioning as large-scale malware distribution. TechRadar adds that SilentPush is warning about the activity and frames it as an IAB-driven effort that leverages compromised websites to deploy a backdoor. Across sources, the common thread is the use of widespread website abuse and redirection to deliver harmful payloads, with the specific methods varying between ClickFix-style interaction manipulation and FakeUpdate-style social engineering. The reporting focuses on observed campaign behavior and indicators of abuse rather than details on how each site was originally compromised.
DriveSurge abuses thousands of compromised websites for ClickFix and FakeUpdate attacks
Multiple reports describe an ongoing campaign attributed to an “initial access broker” (IAB) actor called DriveSurge that compromises or abuses large numbers of websites to redirect visitors to attack...
- DriveSurge is linked to large-scale abuse of thousands of websites.
- A malicious traffic distribution system (TDS) redirects visitors from legitimate sites to attacker-controlled content.
- The campaign uses ClickFix techniques to manipulate user interactions toward malicious outcomes.
- The campaign also uses FakeUpdate prompts to trick users into installing or enabling malware.
- Security researchers attribute the activity to an initial access broker (IAB) style operation.
A sneaky, wide-scale IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware.
2 months agoSilentPush is warning about an Intial Access Broker campaign called DriveSurge that uses thousands of websites to deploy a backdoor.
2 months agoA threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites. [...]
2 months ago
Boy charged with murder after 17-year-old fatally stabbed at Brent council HQ
A 17-year-old teenager is fatally stabbed at Brent council headquarters in Wembley, north-west London. Police arrest a 1...
TestMu Conference 2026 highlights agentic engineering and AI quality focus
TestMu Conference 2026 is held as TestMu AI’s flagship event, with the programme centered on agentic engineering and qua...
Outlets publish ‘five of the best’ home picks for Sydney and Melbourne
Multiple Australian outlets publish curated lists of “five of the best homes” to enjoy both inside and out in major citi...