DriveSurge is a large-scale malware distribution threat cluster assessed to operate primarily as a specialized Initial Access Broker using a pay-per-install model. The actor compromises legitimate websites and injects malicious code that silently redirects visitors to attacker-controlled infrastructure, where victims are funneled into social-engineering-based malware delivery chains. Activity attributed to DriveSurge has been observed at global scale and has affected thousands of compromised websites. DriveSurge is closely associated with two main delivery techniques: FakeUpdates and ClickFix. In FakeUpdates operations, the actor presents fraudulent browser update prompts that impersonate widely used browsers in order to trick users into downloading and executing malware. In ClickFix operations, the actor uses fake verification or error prompts to induce victims to paste attacker-supplied commands into PowerShell on Windows or Terminal on macOS, sometimes with clipboard hijacking to substitute malicious commands. The campaign has targeted both Windows and macOS users. A defining feature of DriveSurge is its use of the open-source zTDS traffic distribution system to profile visitors and dynamically decide which lure, payload path, or redirect chain to serve. Reported infrastructure characteristics indicate a mature and resilient operation, including obfuscated JavaScript injects, API- or orchestrator-style delivery logic, failover mechanisms, and infrastructure patterns that support both active and pre-weaponized staging. The actor has also been linked to advertisement-style distribution components used to fingerprint visitors and verify human interaction before serving malicious content. DriveSurge appears to focus on scalable initial access rather than publicly attributed hands-on-keyboard post-compromise operations. Its role is best understood as supplying downstream threat actors with victim access or installs rather than being tied to a single malware family. No high-confidence public attribution to a specific nation state is established in the available reporting. Known aliases are limited, and DriveSurge is the primary recognized name for this cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
52 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Initial access broker running large-scale malware distribution campaigns via compromised websites, using ClickFix and FakeUpdates and a traffic distribution system on a pay-per-install model.
Uses ClickFix and FakeUpdates to distribute malware via compromised websites.
Associated with abuse of thousands of compromised websites in active ClickFix and FakeUpdates campaigns.
A globally active threat cluster operating as an Initial Access Broker and using a Pay-Per-Install model to compromise legitimate websites and redirect visitors to malware delivery chains.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.