The images in this article were generated with artificial intelligence. How we publish
Silent Push researchers have documented a large-scale campaign that uses legitimate websites committed to distributing malware by two very effective social lures: ClickFix(deception that pushes the victim to copy and execute commands) and FakeUpdates(false browser update notifications). The worrying thing is not just the volume - thousands of hijacked domains - but the infrastructure and business model behind it: DriveSurge operates as a initial access broker (IAB) that monetizes by pay-per-install (IPP), i.e., it sells access or facilities to other criminal operators, multiplying the impact of each commitment. More technical information and examples are available in the Silent Push report: https: / / www.silentpush.com / blog / drivesurge /.
The campaign uses a Traffic Distribution System (TDS) called zTDS to profile those who visit the compromised pages and decide whether to show a FakeUpdate trap or induce the victim to the ClickFix. This selection logic based on browser and system prints increases the success rate: the TDS avoids exposing obvious logic and serves different payloads according to the target, even specific payloads for macOS that are delivered through clipboard manipulations. The use of good reputation sites as a starting point makes it difficult to detect and multiply the exposure of trusted users.

From a technical point of view, Silent Push identified reused patterns (e.g. JavaScript injections with the pattern) t.js? site = < id >) and a list of injection domains and pre-armed domains that have not yet been used, suggesting planning and expansion capacity. For response teams and web administrators, these types of indicators allow you to search for similar commitments in your hosted sites and blocks, but the challenge is that one rule is not enough: attackers rotate domains and opfuscan payloads to evade signatures.
The operational implications are clear: when an actor acts as IAB in an IPP economy, each infection can trigger multiple secondary campaigns (ransomware, credentials theft, fraud, etc.). The commitment of reliable sites erodes confidence in the web ecosystem and turns institutional or business sites into unintended means of attack. In addition, the inclusion of payloads for macOS recalls that the diversity of targets should not be underestimated; defenses must cover multiple platforms.
For end-users, practical recommendations are simple and effective: update software only from the menu of the application itself (e.g. Help > About or Settings > Find updates) not from unverified banners or emerging dialogues; never paste or run commands that appear on a website; and, if the browser shows an update notice, check it from the official section of the browser. CISA offers basic safety and phishing detection tips that can be useful for IT users and equipment: https: / / www.cisa.gov / uscert / ncas / tips / ST04-014.
For site managers and web security equipment it is appropriate to act on three fronts: detection, containment and prevention. In detection, look for injection patterns (e.g. references to t.js? site =..., unexpected external scripts, recent changes to .php / .js files), review HTTP logs and verify external domains contacted by the site. In containment, isolate and restore from clean copies, change credentials and review third party access. In prevention, apply file integrity control, restrictive Content Security Policy (CSP), Subresource Integrity (SRI) where possible, adjusted WAFs to block injections and frequent rotation of credentials and API keys.

Organizations should also consider network and endpoint measures: block at DNS level and proxy the domains and servers associated with the detected distribution infrastructure, deploy EDR protection to capture abnormal behaviors (ZIP downloads that extract DLs / exectable, PowerShell execution with suspicious parameters), and enable navigation isolation for high-risk users. Complementing these measures with specific training in social engineering reduces human exposure, which remains the weakest link.
For product managers and site owners that depend on traffic and reputation, it is critical to understand that a "clean" site can become a vector without notice: to audit third party suppliers, to minimize the inclusion of third party scripts, to use integrity signatures and continuous monitoring, and to establish clear incident response processes. In addition, sharing indicators with CERT teams and security providers helps to contain the campaign at sectoral level.
Finally, the best defense for campaigns that exploit confidence is the combination of technical measures and user habits. Do not run commands from web pages, check updates from the application, keep EDR and WAF updated, and monitor scripts injections are simple steps that significantly reduce the risk. Keeping yourself informed about technical reports (such as Silent Push's) and implementing the recommendations of authorities on cybersecurity helps not to become a major chain of infections.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...