Threats · 104 days ago
Legitimate websites can now be used as silent launchpads for malware. The user starts on a trusted page, gets pushed through a hidden redirect, and lands on a ClickFix or FakeUpdate lure before the original site ever looks suspicious.
Silent Push says DriveSurge hijacked thousands of high-reputation sites with a malicious traffic distribution system, then used that reach to sell initial access through a pay-per-install model. The operation hit Windows and macOS users and stayed hidden for nearly a year, with obfuscated JavaScript and fallback infrastructure keeping the delivery path alive.
The shift is commercial. Initial access is being packaged as a repeatable service, which lowers the barrier for downstream actors and turns normal web traffic into a resale channel for infections.
2 sources covering this story
DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate
A sneaky IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware.
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites.
Part of the PlainSec briefing for 2026-06-03