Legitimate websites can now be used as silent launchpads for malware. The user starts on a trusted page, gets pushed through a hidden redirect, and lands on a ClickFix or FakeUpdate lure before the original site ever looks suspicious.
Silent Push says DriveSurge hijacked thousands of high-reputation sites with a malicious traffic distribution system, then used that reach to sell initial access through a pay-per-install model. The operation hit Windows and macOS users and stayed hidden for nearly a year, with obfuscated JavaScript and fallback infrastructure keeping the delivery path alive.
The shift is commercial. Initial access is being packaged as a repeatable service, which lowers the barrier for downstream actors and turns normal web traffic into a resale channel for infections.