DriveSurge: the IAB that monetizes each infection using legitimate and misleading sites such as ClickFix and FakeUpdates

Author: Published 4 min de lectura 178 reading

The images in this article were generated with artificial intelligence. How we publish

Silent Push researchers have documented a large-scale campaign that uses legitimate websites committed to distributing malware by two very effective social lures: ClickFix(deception that pushes the victim to copy and execute commands) and FakeUpdates(false browser update notifications). The worrying thing is not just the volume - thousands of hijacked domains - but the infrastructure and business model behind it: DriveSurge operates as a initial access broker (IAB) that monetizes by pay-per-install (IPP), i.e., it sells access or facilities to other criminal operators, multiplying the impact of each commitment. More technical information and examples are available in the Silent Push report: https: / / www.silentpush.com / blog / drivesurge /.

The campaign uses a Traffic Distribution System (TDS) called zTDS to profile those who visit the compromised pages and decide whether to show a FakeUpdate trap or induce the victim to the ClickFix. This selection logic based on browser and system prints increases the success rate: the TDS avoids exposing obvious logic and serves different payloads according to the target, even specific payloads for macOS that are delivered through clipboard manipulations. The use of good reputation sites as a starting point makes it difficult to detect and multiply the exposure of trusted users.

DriveSurge: the IAB that monetizes each infection using legitimate and misleading sites such as ClickFix and FakeUpdates
Image generated with IA.

From a technical point of view, Silent Push identified reused patterns (e.g. JavaScript injections with the pattern) t.js? site = < id >) and a list of injection domains and pre-armed domains that have not yet been used, suggesting planning and expansion capacity. For response teams and web administrators, these types of indicators allow you to search for similar commitments in your hosted sites and blocks, but the challenge is that one rule is not enough: attackers rotate domains and opfuscan payloads to evade signatures.

The operational implications are clear: when an actor acts as IAB in an IPP economy, each infection can trigger multiple secondary campaigns (ransomware, credentials theft, fraud, etc.). The commitment of reliable sites erodes confidence in the web ecosystem and turns institutional or business sites into unintended means of attack. In addition, the inclusion of payloads for macOS recalls that the diversity of targets should not be underestimated; defenses must cover multiple platforms.

For end-users, practical recommendations are simple and effective: update software only from the menu of the application itself (e.g. Help > About or Settings > Find updates) not from unverified banners or emerging dialogues; never paste or run commands that appear on a website; and, if the browser shows an update notice, check it from the official section of the browser. CISA offers basic safety and phishing detection tips that can be useful for IT users and equipment: https: / / www.cisa.gov / uscert / ncas / tips / ST04-014.

For site managers and web security equipment it is appropriate to act on three fronts: detection, containment and prevention. In detection, look for injection patterns (e.g. references to t.js? site =..., unexpected external scripts, recent changes to .php / .js files), review HTTP logs and verify external domains contacted by the site. In containment, isolate and restore from clean copies, change credentials and review third party access. In prevention, apply file integrity control, restrictive Content Security Policy (CSP), Subresource Integrity (SRI) where possible, adjusted WAFs to block injections and frequent rotation of credentials and API keys.

DriveSurge: the IAB that monetizes each infection using legitimate and misleading sites such as ClickFix and FakeUpdates
Image generated with IA.

Organizations should also consider network and endpoint measures: block at DNS level and proxy the domains and servers associated with the detected distribution infrastructure, deploy EDR protection to capture abnormal behaviors (ZIP downloads that extract DLs / exectable, PowerShell execution with suspicious parameters), and enable navigation isolation for high-risk users. Complementing these measures with specific training in social engineering reduces human exposure, which remains the weakest link.

For product managers and site owners that depend on traffic and reputation, it is critical to understand that a "clean" site can become a vector without notice: to audit third party suppliers, to minimize the inclusion of third party scripts, to use integrity signatures and continuous monitoring, and to establish clear incident response processes. In addition, sharing indicators with CERT teams and security providers helps to contain the campaign at sectoral level.

Finally, the best defense for campaigns that exploit confidence is the combination of technical measures and user habits. Do not run commands from web pages, check updates from the application, keep EDR and WAF updated, and monitor scripts injections are simple steps that significantly reduce the risk. Keeping yourself informed about technical reports (such as Silent Push's) and implementing the recommendations of authorities on cybersecurity helps not to become a major chain of infections.

Coverage

Related

More news on the same subject.