PULSE NAME
A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
WHITE DriveSurge AlienVault 2026-05-30 Modified: 2026-06-01
35
IOCs
MEDIUM VOLUME
DriveSurge is a newly identified threat actor operating as an Initial Access Broker using a Pay-Per-Install model to supply victim leads to downstream actors. The actor has compromised thousands of websites, injecting malicious code that redirects visitors through zTDS (Traffic Distribution System) to deliver malware via two primary methods: FakeUpdates, which impersonate browser update prompts for Chrome, Firefox, Edge, Safari, and eight other browsers; and ClickFix, which tricks users into executing malicious PowerShell commands disguised as fixes. DriveSurge leverages sophisticated infrastructure including bulletproof hosting, obfuscated JavaScript injection patterns, and environment-specific targeting including macOS systems. The operation has been active since at least September 2025, utilizing specific technical fingerprints including unique file naming conventions and server configurations that enable detection and tracking of their evolving infrastructure.
Indicators of Compromise (2 / 35 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0ca424475803a1cb54908a81a00bd93f 2026-05-30
FileHash-MD5 f3926add1a4531ff324a6acb57d40769 2026-05-30