Nora
Blake

DriveSurge Malware Campaign Hijacks Websites for ClickFix and FakeUpdate Attacks

Nora Blake

Jun 3, 2026

6 min read

DriveSurge Malware Campaign Hijacks Websites for ClickFix and FakeUpdate Attacks

TL; DR

The DriveSurge malware campaign uses compromised websites to redirect visitors to malware-delivery infrastructure that serves ClickFix and FakeUpdates lures.

The operation appears to function as an initial access broker. It uses traffic profiling to determine which social engineering technique to present to each potential victim.

Because the campaign targets both Windows and macOS users and relies on trusted websites, organizations should strengthen:

  • Endpoint security
  • Application controls
  • User awareness
  • Threat detection capabilities

These measures can help reduce the risk of infection.

Understanding the DriveSurge Malware Campaign

A website that appears completely legitimate can still become part of a malware delivery chain.

The DriveSurge malware campaign, publicly reported in June 2026, uses compromised websites to redirect visitors to attacker-controlled infrastructure.

This infrastructure delivers:

  • ClickFix lures
  • FakeUpdates lures
  • Fake browser-update prompts
  • Command-execution instructions

The campaign profiles visitors before selecting which lure to display. These techniques can lead to malware execution on Windows and macOS systems.

The activity shows how attackers combine compromised websites, social engineering, and endpoint-focused malware delivery to gain an initial foothold inside organizations.

Strengthen Endpoint Security with Hexnode

Who Is DriveSurge?

DriveSurge is a threat actor associated with large-scale malware distribution operations.

Researchers describe the group as operating similarly to an initial access broker. It distributes malware through compromised websites and traffic-redirection infrastructure.

Rather than focusing on one malware family, DriveSurge appears to provide access opportunities for downstream threat actors through a pay-per-install model.

The group uses a traffic distribution system to evaluate visitors and determine which lure or payload to deliver.

DriveSurge combines several infection techniques:

  • FakeUpdates pages
  • ClickFix attacks
  • Browser-update impersonation
  • Cross-platform malware delivery

By abusing already-compromised legitimate websites, the campaign can make malicious redirects appear less suspicious to users.

How the Attack Works

Category  Details 
Reporting period  June 2026 
Threat actor  DriveSurge 
Initial access method  Compromised websites redirecting visitors 
Delivery mechanism  Traffic distribution system (zTDS) 
Social engineering techniques  ClickFix and FakeUpdates lures 
Target platforms  Windows and macOS 
Browser themes abused  Chrome, Firefox, Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, UC Browser, and other browser update themes 
User action required  Downloading files or executing commands 
Campaign type  Malware delivery and initial access activity 
Confirmed infrastructure  More than 80 malicious injection and related domains identified 
Primary risk  Malware infection and follow-on compromise

Key Findings from the Investigation

Researchers observed thousands of compromised legitimate websites redirecting visitors to infrastructure associated with the DriveSurge malware campaign.

The operation uses a traffic distribution system known as zTDS to profile visitors based on factors such as browser type, operating system, and context before selecting which lure to display.

FakeUpdates Malware Delivery

FakeUpdates pages impersonate browser update notifications and encourage users to download files used for malware delivery.

ClickFix Attacks and Command Execution

ClickFix attacks rely on social engineering to persuade users to copy and execute commands on their own systems.

In Windows environments, these commands may involve PowerShell.

On macOS, researchers observed clipboard-manipulation techniques that attempted to influence command execution through Terminal.

Why XDR Is Stronger With UEM
Featured resource

Why XDR Is Stronger With UEM

See how combining UEM and XDR bridges the security gap, using UEM as a proactive shield and XDR as a reactive sword to accelerate incident response.

Download the whitepaper

What Is ClickFix?

ClickFix is a social engineering technique that persuades users to perform the malicious action themselves rather than relying on a traditional software exploit.

Victims are typically instructed to copy and run commands through:

  • Command Prompt
  • PowerShell
  • Terminal

The attacker therefore relies on user-executed commands to initiate malicious activity.

What Remains Unclear

While researchers identified infrastructure and delivery mechanisms associated with the campaign, the full range of malware families distributed through the operation has not been publicly detailed.

It is also unclear how many organizations or users may have been successfully infected through the campaign.

Why the DriveSurge Campaign Matters

The DriveSurge malware campaign demonstrates how trusted websites can become part of an attack chain without users realizing it.

Traditional security approaches often focus on blocking known malicious websites. However, DriveSurge compromises legitimate sites and selectively redirects visitors through a traffic distribution system.

This can make malicious activity harder for users and basic URL-blocking controls to recognize.

The campaign also highlights the risks of social engineering techniques that persuade users to run commands through:

  • Command Prompt
  • PowerShell
  • Terminal

Instead of exploiting a software vulnerability directly, the attacker convinces the user to initiate execution.

This can reduce the effectiveness of controls focused only on malicious downloads. It also increases the importance of command-line and process monitoring.

Organizations need visibility into:

  • Device activity
  • Script execution
  • Application installation behavior
  • Suspicious endpoint actions

This visibility can help identify threats before they develop into larger security incidents.

How Hexnode Can Help Reduce Risk

Hexnode UEM: Control Unauthorized Software Installation

The DriveSurge malware campaign relies on users downloading and executing files from untrusted sources.

Hexnode UEM can help organizations enforce application management policies, maintain device compliance, and manage app installation or restriction workflows on supported managed endpoints.

When configured appropriately, these controls can help reduce the risk of unauthorized applications being installed on corporate devices.

Hexnode XDR: Investigate and Respond to Suspicious Endpoint Activity

ClickFix attacks frequently depend on users executing commands that may launch scripts, malware loaders, or follow-on payloads.

Hexnode XDR helps security teams investigate suspicious endpoint activity through endpoint-focused detection, investigation, and response capabilities.

Security teams can use endpoint telemetry and investigation workflows to review suspicious process behavior and activity that may be associated with malware execution.

Security Investigation and Response

Analysts can use Hexnode XDR response actions such as device isolation and process termination to support endpoint incident remediation workflows.

Reducing Exposure to ClickFix and FakeUpdates Malware

The DriveSurge operation illustrates how modern malware campaigns increasingly blend social engineering, compromised websites, and targeted delivery infrastructure.

Users may encounter what appears to be a routine browser update or a harmless instruction to paste a command into a terminal window. In reality, these interactions can provide attackers with an opportunity to establish an initial foothold on a device.

Organizations should review browser security practices, restrict unauthorized software installations, monitor script execution activity, and educate users about the risks of unexpected update prompts and command-execution requests.

Recommended Security Measures

Strengthen Endpoint Controls

Implement application controls, device compliance policies, and software installation restrictions to reduce malware exposure.

Improve User Awareness

Train users to recognize fake browser updates, suspicious prompts, and requests to execute commands in PowerShell, Command Prompt, or Terminal.

Enhance Threat Detection

Use endpoint monitoring and investigation capabilities to identify suspicious processes, script execution, and malware-related activity as early as possible.

Combining endpoint hardening, application controls, security awareness, and endpoint investigation capabilities can help reduce exposure to malware delivery campaigns. Maintaining visibility across managed devices remains an important part of reducing initial-access risk.

Share

Nora Blake

I write at the intersection of technology, process, and people, focusing on explaining complex products with clarity. I break down tools, systems, and workflows without any noise, jargon, or the hype.