PULSE NAME
A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
WHITE DriveSurge AlienVault 2026-06-01 Modified: 2026-06-02
34
IOCs
MEDIUM VOLUME
A sophisticated threat actor named DriveSurge operates as an Initial Access Broker using a Pay-Per-Install model to deliver malware at scale. The actor compromises thousands of legitimate websites and uses zTDS (Traffic Distribution System) to silently redirect visitors to malicious content. Victims encounter either FakeUpdates campaigns that impersonate browser update prompts for 11 different browsers, or ClickFix attacks that trick users into executing malicious commands through fake error messages. DriveSurge's infrastructure utilizes bulletproof hosting services, primarily NiceNIC registrar, and has been operating since at least 2015. The campaigns target both Windows and macOS systems, employing sophisticated obfuscation techniques and clipboard hijacking to achieve infection. Eight technical fingerprints have been identified to track this actor's infrastructure and activities.
Indicators of Compromise (2 / 34 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0ca424475803a1cb54908a81a00bd93f 2026-06-01
FileHash-MD5 f3926add1a4531ff324a6acb57d40769 2026-06-01