The DriveSurge malware campaign uses compromised websites to redirect visitors to malware-delivery infrastructure that serves ClickFix and FakeUpdates lures.
The operation appears to function as an initial access broker. It uses traffic profiling to determine which social engineering technique to present to each potential victim.
Because the campaign targets both Windows and macOS users and relies on trusted websites, organizations should strengthen:
Endpoint security
Application controls
User awareness
Threat detection capabilities
These measures can help reduce the risk of infection.
A website that appears completely legitimate can still become part of a malware delivery chain.
The DriveSurge malware campaign, publicly reported in June 2026, uses compromised websites to redirect visitors to attacker-controlled infrastructure.
This infrastructure delivers:
ClickFix lures
FakeUpdates lures
Fake browser-update prompts
Command-execution instructions
The campaign profiles visitors before selecting which lure to display. These techniques can lead to malware execution on Windows and macOS systems.
The activity shows how attackers combine compromised websites, social engineering, and endpoint-focused malware delivery to gain an initial foothold inside organizations.
DriveSurge is a threat actor associated with large-scale malware distribution operations.
Researchers describe the group as operating similarly to an initial access broker. It distributes malware through compromised websites and traffic-redirection infrastructure.
Rather than focusing on one malware family, DriveSurge appears to provide access opportunities for downstream threat actors through a pay-per-install model.
The group uses a traffic distribution system to evaluate visitors and determine which lure or payload to deliver.
DriveSurge combines several infection techniques:
FakeUpdates pages
ClickFix attacks
Browser-update impersonation
Cross-platform malware delivery
By abusing already-compromised legitimate websites, the campaign can make malicious redirects appear less suspicious to users.
How the Attack Works
Category
Details
Reporting period
June 2026
Threat actor
DriveSurge
Initial access method
Compromised websites redirecting visitors
Delivery mechanism
Traffic distribution system (zTDS)
Social engineering techniques
ClickFix and FakeUpdates lures
Target platforms
Windows and macOS
Browser themes abused
Chrome, Firefox, Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, UC Browser, and other browser update themes
Researchers observed thousands of compromised legitimate websites redirecting visitors to infrastructure associated with the DriveSurge malware campaign.
The operation uses a traffic distribution system known as zTDS to profile visitors based on factors such as browser type, operating system, and context before selecting which lure to display.
FakeUpdates Malware Delivery
FakeUpdates pages impersonate browser update notifications and encourage users to download files used for malware delivery.
ClickFix Attacks and Command Execution
ClickFix attacks rely on social engineering to persuade users to copy and execute commands on their own systems.
In Windows environments, these commands may involve PowerShell.
On macOS, researchers observed clipboard-manipulation techniques that attempted to influence command execution through Terminal.
Featured resource
Why XDR Is Stronger With UEM
See how combining UEM and XDR bridges the security gap, using UEM as a proactive shield and XDR as a reactive sword to accelerate incident response.
ClickFix is a social engineering technique that persuades users to perform the malicious action themselves rather than relying on a traditional software exploit.
Victims are typically instructed to copy and run commands through:
Command Prompt
PowerShell
Terminal
The attacker therefore relies on user-executed commands to initiate malicious activity.
What Remains Unclear
While researchers identified infrastructure and delivery mechanisms associated with the campaign, the full range of malware families distributed through the operation has not been publicly detailed.
It is also unclear how many organizations or users may have been successfully infected through the campaign.
Why the DriveSurge Campaign Matters
The DriveSurge malware campaign demonstrates how trusted websites can become part of an attack chain without users realizing it.
Traditional security approaches often focus on blocking known malicious websites. However, DriveSurge compromises legitimate sites and selectively redirects visitors through a traffic distribution system.
This can make malicious activity harder for users and basic URL-blocking controls to recognize.
The campaign also highlights the risks of social engineering techniques that persuade users to run commands through:
Command Prompt
PowerShell
Terminal
Instead of exploiting a software vulnerability directly, the attacker convinces the user to initiate execution.
This can reduce the effectiveness of controls focused only on malicious downloads. It also increases the importance of command-line and process monitoring.
Organizations need visibility into:
Device activity
Script execution
Application installation behavior
Suspicious endpoint actions
This visibility can help identify threats before they develop into larger security incidents.
Vulnerability Assessment with Hexnode UEM + XDR
Explore how UEM and XDR enables organizations to shift from static vulnerability scanning to real-time threat detection.
How Hexnode Can Help Reduce Risk
Hexnode UEM: Control Unauthorized Software Installation
The DriveSurge malware campaign relies on users downloading and executing files from untrusted sources.
Hexnode UEM can help organizations enforce application management policies, maintain device compliance, and manage app installation or restriction workflows on supported managed endpoints.
When configured appropriately, these controls can help reduce the risk of unauthorized applications being installed on corporate devices.
Hexnode XDR: Investigate and Respond to Suspicious Endpoint Activity
ClickFix attacks frequently depend on users executing commands that may launch scripts, malware loaders, or follow-on payloads.
Hexnode XDR helps security teams investigate suspicious endpoint activity through endpoint-focused detection, investigation, and response capabilities.
Security teams can use endpoint telemetry and investigation workflows to review suspicious process behavior and activity that may be associated with malware execution.
Security Investigation and Response
Analysts can use Hexnode XDR response actions such as device isolation and process termination to support endpoint incident remediation workflows.
Reducing Exposure to ClickFix and FakeUpdates Malware
The DriveSurge operation illustrates how modern malware campaigns increasingly blend social engineering, compromised websites, and targeted delivery infrastructure.
Users may encounter what appears to be a routine browser update or a harmless instruction to paste a command into a terminal window. In reality, these interactions can provide attackers with an opportunity to establish an initial foothold on a device.
Organizations should review browser security practices, restrict unauthorized software installations, monitor script execution activity, and educate users about the risks of unexpected update prompts and command-execution requests.
Recommended Security Measures
Strengthen Endpoint Controls
Implement application controls, device compliance policies, and software installation restrictions to reduce malware exposure.
Improve User Awareness
Train users to recognize fake browser updates, suspicious prompts, and requests to execute commands in PowerShell, Command Prompt, or Terminal.
Enhance Threat Detection
Use endpoint monitoring and investigation capabilities to identify suspicious processes, script execution, and malware-related activity as early as possible.
Combining endpoint hardening, application controls, security awareness, and endpoint investigation capabilities can help reduce exposure to malware delivery campaigns. Maintaining visibility across managed devices remains an important part of reducing initial-access risk.
Stay Ahead of Emerging Cyber Threats
Learn how to reduce endpoint risk, improve threat visibility, and strengthen your organization's security posture.
I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.