Trusted Sites Became Malware Delivery Hops

Legitimate websites can now be used as silent launchpads for malware. The user starts on a trusted page, gets pushed through a hidden redirect, and lands on a ClickFix or FakeUpdate lure before the original site ever looks suspicious. Silent Push says DriveSurge hijacked thousands of high-reputation sites with a malicious traffic distribution system, then used that reach to sell initial access through a pay-per-install model. The operation hit Windows and macOS users and stayed hidden for nearly a year, with obfuscated JavaScript and fallback infrastructure keeping the delivery path alive. The shift is commercial. Initial access is being packaged as a repeatable service, which lowers the barrier for downstream actors and turns normal web traffic into a resale channel for infections.

Part of the PlainSec briefing for 2026-06-03

Sources