A threat actor tracked as DriveSurge has been running large-scale malware distribution campaigns by abusing compromised websites and using ClickFix and FakeUpdates tactics to infect visitors.
According to researchers at cybersecurity company Silent Push, thousands of websites have been compromised in these campaigns and used to redirect visitors to malware delivery infrastructure. The attacks rely on social engineering methods that trick users into either running malicious commands or downloading fake software updates.
ClickFix is a tactic where victims are fooled into copying and executing harmful commands on their systems, often under the false claim that they need to fix a technical issue. FakeUpdates attacks work differently, showing users fake browser or software update alerts that push them into downloading and installing malicious files.
Silent Push says DriveSurge mainly acts as an initial access broker operating on a pay-per-install model. This means the group focuses on getting malware onto victims’ systems and then enabling further attacks by other threat actors.
Visitors who land on compromised websites are redirected through a traffic distribution system known as zTDS. This system profiles each visitor and decides whether a FakeUpdates lure or a ClickFix trick is more likely to work.
zTDS is an open-source traffic distribution system that has existed since at least 2015. Silent Push says DriveSurge has been using it since at least September 2025 to hijack legitimate, high-reputation websites and quietly redirect visitors to malware without the knowledge of site owners or users.
The FakeUpdates lures used in the campaign impersonate update prompts for several popular browsers, including Chrome, Firefox, Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, and UC Browser. The ClickFix attacks, meanwhile, involve malicious PowerShell commands.
In one example highlighted by Silent Push, victims were shown a fake Firefox update that downloaded a ZIP archive containing several DLL files and a malicious executable named “Browser Update.exe.”
Researchers also identified eight technical fingerprints connected to the campaign, helping them track DriveSurge infrastructure and compromised websites. One of the key indicators was a JavaScript injection using the pattern “t.js?site=,” where each compromised site had its own unique ID.
Through their analysis, Silent Push found more than 80 malicious injection domains, along with several pre-weaponized domains that had not yet been used in active attacks.
The researchers also discovered an obfuscated JavaScript payload designed to target macOS desktop systems. It was delivered through verification-themed ClickFix attacks that hijacked the clipboard, showing that the campaign is not limited to Windows users.
Users are advised to download browser updates only through the browser’s built-in settings menu, such as About and Check for Updates. They should also avoid copying or running commands in Windows Command Prompt, PowerShell, or Terminal unless they fully understand what the command does.





