PULSE NAME
A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
WHITE DriveSurge AlienVault 2026-05-30 Modified: 2026-06-01
35
IOCs
MEDIUM VOLUME
DriveSurge is a newly identified threat actor operating as an Initial Access Broker using a Pay-Per-Install model to supply victim leads to downstream actors. The actor has compromised thousands of websites, injecting malicious code that redirects visitors through zTDS (Traffic Distribution System) to deliver malware via two primary methods: FakeUpdates, which impersonate browser update prompts for Chrome, Firefox, Edge, Safari, and eight other browsers; and ClickFix, which tricks users into executing malicious PowerShell commands disguised as fixes. DriveSurge leverages sophisticated infrastructure including bulletproof hosting, obfuscated JavaScript injection patterns, and environment-specific targeting including macOS systems. The operation has been active since at least September 2025, utilizing specific technical fingerprints including unique file naming conventions and server configurations that enable detection and tracking of their evolving infrastructure.
Indicators of Compromise (35)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0ca424475803a1cb54908a81a00bd93f 2026-05-30
FileHash-MD5 f3926add1a4531ff324a6acb57d40769 2026-05-30
FileHash-SHA1 a4f0014474278238b5fe78fc2c4182b498012a33 2026-05-30
FileHash-SHA256 0c62c11e910d7c0d6b6c9800b70e78bfd9220e1f78bd7bb34ae4c3646d05f6e5 2026-05-30
FileHash-SHA256 29ac78c51bcdfe68c64830bdeb6e41437dd55e2691149741c9b78be03b6c82ea 2026-05-30
FileHash-SHA256 428bd0b0ac36dfdd223b3953dbe61c0baf227f893310b03e7afe3111462019c6 2026-05-30
FileHash-SHA256 7aa15de93cf85729ddf970e8d7897f69ece3ca29608f73e784a9ba40c9cea18d 2026-05-30
FileHash-SHA256 90aecb370dfb1a99a1f7de0a9c6842ab1b664521fddea16b0ec9a91f322646fc 2026-05-30
FileHash-SHA256 a84b032b49773c2318b11b1164d1aada69e940229aedbf8185c33fc7dd1d2cdf 2026-05-30
IPv4 147.45.42.200 2026-05-30
IPv4 147.45.42.205 2026-05-30
IPv4 46.226.166.57 2026-05-30
IPv4 91.92.240.127 2026-05-30
URL http://bseolized.com 2026-05-30
URL http://newtdsone.shop/jsrepo?rnd= 2026-05-30
domain beacontrace.bond 2026-05-30
domain brightson.icu 2026-05-30
domain bseolized.com 2026-05-30
domain captioto.com 2026-05-30
domain coverlink.icu 2026-05-30
domain cptoptious.com 2026-05-30
domain datumprobe.icu 2026-05-30
domain eraggifts.icu 2026-05-30
domain jcdlforwarding.com 2026-05-30
domain jclforwarding.com 2026-05-30
domain keyview.icu 2026-05-30
domain maxintora.com 2026-05-30
domain newtdsone.shop 2026-05-30
domain traceglimpse.icu 2026-05-30
domain tracekey.icu 2026-05-30
domain webgleam.info 2026-05-30
domain ycyfugihih.cfd 2026-05-30
domain ztds.info 2026-05-30
hostname check.first-node.rocks 2026-05-30
hostname testio.ecartdev.com 2026-05-30