DriveSurge is a large-scale malware distribution threat cluster assessed to operate primarily as a specialized Initial Access Broker using a pay-per-install model. The actor compromises legitimate websites and injects malicious code that silently redirects visitors to attacker-controlled infrastructure, allowing downstream operators to acquire victim access at scale. DriveSurge has been linked to widespread ClickFix and FakeUpdates campaigns and has abused thousands of compromised websites globally. The actor uses the open-source zTDS traffic distribution system to profile incoming visitors and selectively deliver social-engineering lures. Its FakeUpdates activity impersonates browser update prompts across multiple major browsers to induce victims to download and execute malware. Its ClickFix activity relies on fake verification or error dialogs that trick users into pasting attacker-supplied commands into PowerShell on Windows or Terminal on macOS. Researchers also observed clipboard hijacking and orchestrated multi-stage delivery flows designed to reduce visibility and improve execution success. DriveSurge targets both Windows and macOS users. Reported infrastructure and delivery patterns show emphasis on stealthy web-based initial access, malicious JavaScript injection, traffic filtering, redirect chains, and resilient failover mechanisms. The operation has been associated with multiple recurring infrastructure fingerprints, including distinctive injected script patterns, hashed JavaScript naming conventions, centralized domain-registration behaviors, and extensive use of traffic-distribution infrastructure. The campaign has also been tied to an advertisement-style distribution component that fingerprints users and verifies human interaction before serving malicious content. DriveSurge is notable for enabling follow-on compromise rather than being tied to a single malware family or extortion brand. Its core role is brokering access and distributing payloads for other threat actors through compromised web ecosystems. No high-confidence attribution to a nation-state is established in the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
52 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access broker running large-scale malware distribution campaigns via compromised websites, using ClickFix and FakeUpdates and a traffic distribution system on a pay-per-install model.
Uses ClickFix and FakeUpdates to distribute malware via compromised websites.
Associated with abuse of thousands of compromised websites in active ClickFix and FakeUpdates campaigns.
A globally active threat cluster operating as an Initial Access Broker and using a Pay-Per-Install model to compromise legitimate websites and redirect visitors to malware delivery chains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.