{"id":1105,"date":"2026-06-03T16:11:49","date_gmt":"2026-06-03T10:41:49","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=1105"},"modified":"2026-08-19T16:16:08","modified_gmt":"2026-08-19T10:46:08","slug":"drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/","title":{"rendered":"DriveSurge Malware Campaign Hijacks Websites for ClickFix and FakeUpdate Attacks"},"content":{"rendered":"<h2>Understanding the DriveSurge Malware Campaign<\/h2>\n<p>A website that appears completely legitimate can still become part of a malware delivery chain.<\/p>\n<p>The DriveSurge malware campaign, publicly reported in June 2026, uses compromised websites to redirect visitors to attacker-controlled infrastructure.<\/p>\n<p>This infrastructure delivers:<\/p>\n<ul>\n<li>ClickFix lures<\/li>\n<li>FakeUpdates lures<\/li>\n<li>Fake browser-update prompts<\/li>\n<li>Command-execution instructions<\/li>\n<\/ul>\n<p>The campaign profiles visitors before selecting which lure to display. These techniques can lead to malware execution on Windows and macOS systems.<\/p>\n<p>The activity shows how attackers combine compromised websites, social engineering, and endpoint-focused malware delivery to gain an initial foothold inside organizations.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" target=\"_blank\">\r\n    \t\tStrengthen Endpoint Security with Hexnode <\/a>\r\n    \t\t<\/center><\/p>\n<h3>Who Is DriveSurge?<\/h3>\n<p>DriveSurge is a threat actor associated with large-scale malware distribution operations.<\/p>\n<p>Researchers describe the group as operating similarly to an initial access broker. It distributes malware through compromised websites and traffic-redirection infrastructure.<\/p>\n<p>Rather than focusing on one malware family, DriveSurge appears to provide access opportunities for downstream threat actors through a pay-per-install model.<\/p>\n<p>The group uses a traffic distribution system to evaluate visitors and determine which lure or payload to deliver.<\/p>\n<p>DriveSurge combines several infection techniques:<\/p>\n<ul>\n<li>FakeUpdates pages<\/li>\n<li>ClickFix attacks<\/li>\n<li>Browser-update impersonation<\/li>\n<li>Cross-platform malware delivery<\/li>\n<\/ul>\n<p>By abusing already-compromised legitimate websites, the campaign can make malicious redirects appear less suspicious to users.<\/p>\n<h2>How the Attack Works<\/h2>\n<table style=\"font-weight: 400;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"12\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Category<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Details<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Reporting period<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">June 2026<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Threat actor<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">DriveSurge<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Initial access method<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Compromised websites redirecting visitors<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Delivery mechanism<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Traffic distribution system (zTDS)<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"6\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Social engineering techniques<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">ClickFix\u00a0and\u00a0FakeUpdates\u00a0lures<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"7\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Target platforms<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Windows and macOS<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"8\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Browser themes abused<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Chrome, Firefox, Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, UC Browser, and other browser update themes<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559738&quot;:240,&quot;335559739&quot;:240}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"9\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">User action\u00a0required<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Downloading files or executing\u00a0commands<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"10\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Campaign\u00a0type<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Malware delivery and initial access activity<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"11\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Confirmed infrastructure<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/hackers-hijack-thousands-of-sites-for-clickfix-and-fakeupdate-attacks\/?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=drivesurge_malware_campaign\" target=\"_blank\" rel=\"nofollow noreferrer noopener\"><span data-contrast=\"auto\">More than 80 malicious injection and related domains\u00a0identified<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/a><\/td>\n<\/tr>\n<tr aria-rowindex=\"12\">\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Primary risk<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Malware infection and follow-on compromise<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>Key Findings from the Investigation<\/h3>\n<p>Researchers observed thousands of compromised legitimate websites redirecting visitors to infrastructure associated with the DriveSurge malware campaign.<\/p>\n<p>The operation uses a traffic distribution system known as zTDS to profile visitors based on factors such as browser type, operating system, and context before selecting which lure to display.<\/p>\n<h4>FakeUpdates Malware Delivery<\/h4>\n<p>FakeUpdates pages impersonate browser update notifications and encourage users to download files used for malware delivery.<\/p>\n<h4>ClickFix Attacks and Command Execution<\/h4>\n<p>ClickFix attacks rely on social engineering to persuade users to copy and execute commands on their own systems.<\/p>\n<p>In <a href=\"https:\/\/www.hexnode.com\/uem\/platform\/windows-mdm\/\">Windows<\/a> environments, these commands may involve PowerShell.<\/p>\n<p>On <a href=\"https:\/\/www.hexnode.com\/uem\/platform\/macos-device-management\/\">macOS<\/a>, researchers observed clipboard-manipulation techniques that attempted to influence command execution through Terminal.<br \/>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1.webp?format=webp\" class=\"resource-box__image\" alt=\"Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1.webp?format=webp 287w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300-1-96x100.webp?format=webp 96w\" sizes=\"auto, (max-width: 287px) 100vw, 287px\" title=\"Why-XDR-IS-stronger-thumbnail-1-e1779299236694-287x300\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Why XDR Is Stronger With UEM\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            See how combining UEM and XDR bridges the security gap, using UEM as a proactive shield and XDR as a reactive sword to accelerate incident response.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/why-xdr-is-stronger-with-uem\/'>\n                            Download the whitepaper\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section><\/p>\n<h3>What Is ClickFix?<\/h3>\n<p>ClickFix is a social engineering technique that persuades users to perform the malicious action themselves rather than relying on a traditional software exploit.<\/p>\n<p>Victims are typically instructed to copy and run commands through:<\/p>\n<ul>\n<li>Command Prompt<\/li>\n<li>PowerShell<\/li>\n<li>Terminal<\/li>\n<\/ul>\n<p>The attacker therefore relies on user-executed commands to initiate malicious activity.<\/p>\n<h3>What Remains Unclear<\/h3>\n<p>While researchers identified infrastructure and delivery mechanisms associated with the campaign, the full range of malware families distributed through the operation has not been publicly detailed.<\/p>\n<p>It is also unclear how many organizations or users may have been successfully infected through the campaign.<\/p>\n<h2>Why the DriveSurge Campaign Matters<\/h2>\n<p>The DriveSurge malware campaign demonstrates how trusted websites can become part of an <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-an-attack-chain\/\">attack chain<\/a> without users realizing it.<\/p>\n<p>Traditional security approaches often focus on blocking known malicious websites. However, DriveSurge compromises legitimate sites and selectively redirects visitors through a traffic distribution system.<\/p>\n<p>This can make malicious activity harder for users and basic URL-blocking controls to recognize.<\/p>\n<p>The campaign also highlights the risks of social engineering techniques that persuade users to run commands through:<\/p>\n<ul>\n<li>Command Prompt<\/li>\n<li>PowerShell<\/li>\n<li>Terminal<\/li>\n<\/ul>\n<p>Instead of exploiting a software vulnerability directly, the attacker convinces the user to initiate execution.<\/p>\n<p>This can reduce the effectiveness of controls focused only on malicious downloads. It also increases the importance of command-line and process monitoring.<\/p>\n<p>Organizations need visibility into:<\/p>\n<ul>\n<li>Device activity<\/li>\n<li>Script execution<\/li>\n<li>Application installation behavior<\/li>\n<li>Suspicious endpoint actions<\/li>\n<\/ul>\n<p>This visibility can help identify threats before they develop into larger security incidents.<br \/>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Real-Time-Threat-Detection-Hexnode-UEM-XDR-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>Vulnerability Assessment with Hexnode UEM + XDR<\/h4><p>Explore how UEM and XDR enables organizations to shift from static vulnerability scanning to real-time threat detection.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/real-time-threat-detection\/\" aria-label=\"Vulnerability Assessment with Hexnode UEM + XDR\"><\/a><\/div><\/div><\/div><\/p>\n<h2>How Hexnode Can Help Reduce Risk<\/h2>\n<h3>Hexnode UEM: Control Unauthorized Software Installation<\/h3>\n<p>The DriveSurge malware campaign relies on users downloading and executing files from untrusted sources.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> can help organizations enforce application management policies, maintain device compliance, and manage app installation or restriction workflows on supported managed endpoints.<\/p>\n<p>When configured appropriately, these controls can help reduce the risk of unauthorized applications being installed on corporate devices.<\/p>\n<h3>Hexnode XDR: Investigate and Respond to Suspicious Endpoint Activity<\/h3>\n<p>ClickFix attacks frequently depend on users executing commands that may launch scripts, malware loaders, or follow-on payloads.<\/p>\n<p><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> helps security teams investigate suspicious endpoint activity through endpoint-focused detection, investigation, and response capabilities.<\/p>\n<p>Security teams can use endpoint telemetry and investigation workflows to review suspicious process behavior and activity that may be associated with malware execution.<\/p>\n<h4>Security Investigation and Response<\/h4>\n<p>Analysts can use Hexnode XDR response actions such as device isolation and process termination to support endpoint incident remediation workflows.<\/p>\n<h2>Reducing Exposure to ClickFix and FakeUpdates Malware<\/h2>\n<p>The DriveSurge operation illustrates how modern malware campaigns increasingly blend social engineering, compromised websites, and targeted delivery infrastructure.<\/p>\n<p>Users may encounter what appears to be a routine browser update or a harmless instruction to paste a command into a terminal window. In reality, these interactions can provide attackers with an opportunity to establish an initial foothold on a device.<\/p>\n<p>Organizations should review browser security practices, restrict unauthorized software installations, monitor script execution activity, and educate users about the risks of unexpected update prompts and command-execution requests.<\/p>\n<h3>Recommended Security Measures<\/h3>\n<h4>Strengthen Endpoint Controls<\/h4>\n<p>Implement application controls, device compliance policies, and software installation restrictions to reduce malware exposure.<\/p>\n<h4>Improve User Awareness<\/h4>\n<p>Train users to recognize fake browser updates, suspicious prompts, and requests to execute commands in PowerShell, Command Prompt, or Terminal.<\/p>\n<h4>Enhance Threat Detection<\/h4>\n<p>Use <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-endpoint-monitoring\/\">endpoint monitoring<\/a> and investigation capabilities to identify suspicious processes, script execution, and malware-related activity as early as possible.<\/p>\n<p>Combining endpoint hardening, application controls, security awareness, and endpoint investigation capabilities can help reduce exposure to malware delivery campaigns. Maintaining visibility across managed devices remains an important part of reducing initial-access risk.<br \/>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stay Ahead of Emerging Cyber Threats<\/h5><p>Learn how to reduce endpoint risk, improve threat visibility, and strengthen your organization's security posture.<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Try Hexnode Now<\/a><\/div><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Understanding the DriveSurge Malware Campaign A website that appears completely legitimate can still become part&#8230;<\/p>\n","protected":false},"author":4,"featured_media":1106,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[17,21],"class_list":["post-1105","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-macos","category-patch-management","product_category-extended-detection-and-response","tab_group-malware-and-ransomware"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DriveSurge Malware Campaign Uses ClickFix and FakeUpdates<\/title>\n<meta name=\"description\" content=\"Know how DriveSurge malware campaign uses ClickFix and FakeUpdates to deliver malware through compromised websites.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DriveSurge Malware Campaign Uses ClickFix and FakeUpdates\" \/>\n<meta property=\"og:description\" content=\"Know how DriveSurge malware campaign uses ClickFix and FakeUpdates to deliver malware through compromised websites.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-03T10:41:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T10:46:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/DriveSurge-Malware-Campaign-Hijacks-Websites-for-ClickFix-and-FakeUpdate-Attacks.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1500\" \/>\n\t<meta property=\"og:image:height\" content=\"843\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"DriveSurge Malware Campaign Hijacks Websites for ClickFix and FakeUpdate Attacks\",\"datePublished\":\"2026-06-03T10:41:49+00:00\",\"dateModified\":\"2026-08-19T10:46:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\\\/\"},\"wordCount\":1033,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/DriveSurge-Malware-Campaign-Hijacks-Websites-for-ClickFix-and-FakeUpdate-Attacks.jpeg?format=webp\",\"articleSection\":[\"macOS\",\"Patch Management\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\\\/\",\"name\":\"DriveSurge Malware Campaign Uses ClickFix and FakeUpdates\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/DriveSurge-Malware-Campaign-Hijacks-Websites-for-ClickFix-and-FakeUpdate-Attacks.jpeg?format=webp\",\"datePublished\":\"2026-06-03T10:41:49+00:00\",\"dateModified\":\"2026-08-19T10:46:08+00:00\",\"description\":\"Know how DriveSurge malware campaign uses ClickFix and FakeUpdates to deliver malware through compromised websites.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/DriveSurge-Malware-Campaign-Hijacks-Websites-for-ClickFix-and-FakeUpdate-Attacks.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/DriveSurge-Malware-Campaign-Hijacks-Websites-for-ClickFix-and-FakeUpdate-Attacks.jpeg?format=webp\",\"width\":1500,\"height\":843,\"caption\":\"DriveSurge Malware Campaign Hijacks Websites for ClickFix and FakeUpdate Attacks\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DriveSurge Malware Campaign Hijacks Websites for ClickFix and FakeUpdate Attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DriveSurge Malware Campaign Uses ClickFix and FakeUpdates","description":"Know how DriveSurge malware campaign uses ClickFix and FakeUpdates to deliver malware through compromised websites.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/","og_locale":"en_US","og_type":"article","og_title":"DriveSurge Malware Campaign Uses ClickFix and FakeUpdates","og_description":"Know how DriveSurge malware campaign uses ClickFix and FakeUpdates to deliver malware through compromised websites.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-06-03T10:41:49+00:00","article_modified_time":"2026-08-19T10:46:08+00:00","og_image":[{"width":1500,"height":843,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/DriveSurge-Malware-Campaign-Hijacks-Websites-for-ClickFix-and-FakeUpdate-Attacks.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"DriveSurge Malware Campaign Hijacks Websites for ClickFix and FakeUpdate Attacks","datePublished":"2026-06-03T10:41:49+00:00","dateModified":"2026-08-19T10:46:08+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/"},"wordCount":1033,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/DriveSurge-Malware-Campaign-Hijacks-Websites-for-ClickFix-and-FakeUpdate-Attacks.jpeg?format=webp","articleSection":["macOS","Patch Management"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/","url":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/","name":"DriveSurge Malware Campaign Uses ClickFix and FakeUpdates","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/DriveSurge-Malware-Campaign-Hijacks-Websites-for-ClickFix-and-FakeUpdate-Attacks.jpeg?format=webp","datePublished":"2026-06-03T10:41:49+00:00","dateModified":"2026-08-19T10:46:08+00:00","description":"Know how DriveSurge malware campaign uses ClickFix and FakeUpdates to deliver malware through compromised websites.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/DriveSurge-Malware-Campaign-Hijacks-Websites-for-ClickFix-and-FakeUpdate-Attacks.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/DriveSurge-Malware-Campaign-Hijacks-Websites-for-ClickFix-and-FakeUpdate-Attacks.jpeg?format=webp","width":1500,"height":843,"caption":"DriveSurge Malware Campaign Hijacks Websites for ClickFix and FakeUpdate Attacks"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/drivesurge-malware-campaign-hijacks-with-clickfix-and-fakeupdate\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"DriveSurge Malware Campaign Hijacks Websites for ClickFix and FakeUpdate Attacks"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1105","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=1105"}],"version-history":[{"count":1,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1105\/revisions"}],"predecessor-version":[{"id":1107,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/1105\/revisions\/1107"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/1106"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=1105"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=1105"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}