Multiple reports describe an ongoing campaign attributed to an “initial access broker” (IAB) actor called DriveSurge that compromises or abuses large numbers of websites to redirect visitors to attacker-controlled content. According to the reporting, DriveSurge uses a malicious traffic distribution system (TDS) to hijack the normal flow from trusted sites, sending users to pages that deliver malware or attacker infrastructure. The campaign is associated with two techniques: “ClickFix,” which alters or influences user interactions to drive victims toward malicious outcomes, and “FakeUpdate” attacks, which present counterfeit software or update prompts to trick users into installing or enabling malicious payloads. Bleeping Computer and Dark Reading both describe the campaign as affecting thousands of sites and functioning as large-scale malware distribution. TechRadar adds that SilentPush is warning about the activity and frames it as an IAB-driven effort that leverages compromised websites to deploy a backdoor. Across sources, the common thread is the use of widespread website abuse and redirection to deliver harmful payloads, with the specific methods varying between ClickFix-style interaction manipulation and FakeUpdate-style social engineering. The reporting focuses on observed campaign behavior and indicators of abuse rather than details on how each site was originally compromised.