Thousands of compromised websites abused by DriveSurge in active ClickFix and FakeUpdates campaigns
- SilentPush researchers uncovered DriveSurge, a large‑scale ClickFix campaign
- Victims are profiled and served either ClickFix or FakeUpdates
- Access is later sold on the dark web
An ongoing ClickFix campaign has infected thousands of computers with backdoor malware. This is according to security researchers SilentPush, who said the threat actors are selling the access on the dark web.
The campaign, dubbed DriveSurge, starts on poorly secured websites, where criminals inject malicious scripts. These scripts act as lightweight beacons, passing visitor data to a remote Traffic Distribution System (TDS) called zTDS. There, the visitors are evaluated and if deemed a target, the zTDS server instructs the script to load a ClickFix overlay.
Bots and researchers are served the legitimate webpage to avoid being detected.
Thousands of websites used
Depending on the profiling, the victims can be served either ClicFix or FakeUpdates. The goal is the same - the execution just slightly...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE