CyberWire Daily - When trusted sites turn. [Research Saturday]

Episode Date: July 18, 2026

Lauren Fievisohn, Ph.D, Senior Threat Researcher from Silent Push, is sharing their work on "Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Comprom...ised Sites." Silent Push researchers have identified a newly named threat actor, DriveSurge, which has compromised thousands of legitimate websites and uses ClickFix and fake browser update lures to distribute malware at scale through a pay-per-install operation. The group leverages a traffic distribution system called zTDS to silently redirect visitors from trusted websites to malicious payloads, while employing sophisticated infrastructure, obfuscation, and fingerprinting techniques to evade detection. The report also details how DriveSurge targets both Windows and macOS users and provides defenders with eight infrastructure fingerprints to help identify and disrupt the campaign. The research and executive brief can be found here: Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites Learn more about your ad choices. Visit megaphone.fm/adchoices

Transcript
Discussion (0)
Starting point is 00:00:00 You're listening to the Cyberwire Network, powered by N2K. This episode is brought to you by Accenture. When your advertising operations fall out of sync, everything else follows. Spotify and Accenture are working together to reinvent the rhythm of ad sales, using automation, analytics, and smarter workflows to simplify campaign delivery and access better data across the business. The result? Less time spent on operations, more time connecting brands with the moments and fandums
Starting point is 00:00:33 that matter most. Learn more at Accenture.com slash Spotify. This episode is supported by Black Hat USA. If you follow the research, you know a lot of it breaks on Black Hat stages. Hundreds of peer-reviewed briefings, more than 100 hands-on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow. August 1st to the 6th. Prices increased July 17th, so book before then. Use code Cyberwire for $200 off your briefing pass at blackhat.com. We'll see you in Vegas. Hello everyone and welcome to the CyberWire's Research Saturday. I'm Dave Bittner and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities,
Starting point is 00:01:36 solving some of the hard problems and protecting ourselves in a rapidly evolving cyberspace. Thanks for joining us. This M1 in particular, It pulled from two different places. So one is bulletproof hosting providers, particularly one of our recent or past white papers. We've identified Nicnick as a bulletproof hosting provider. So we have that on the one end. And then on the other side, just kind of this idea of, okay, what are general behaviors of bad, you know? So that's the other side.
Starting point is 00:02:16 So we were thinking, okay, let's look at everything that's hosted on NiceNick. and then looking to see of those domains, which ones are providing resources to websites. And through that, you know, kind of looking at these behaviors, we found this big cluster that we have said is drive surge. That's Lauren Fivison, senior threat researcher from Silent Push. The research we're discussing today is titled Meet Drive Surge, a new threat actor using click-fix and fake update drive-by attacks in thousands of compromise sites. So I think probably most of our listeners are familiar with things like click fix and fake updates. At what point did this activity stop looking like them and start looking like its own coordinated operation? So the interesting thing, and so I'd say like click fix and fake updates, I won't say it's a group.
Starting point is 00:03:25 And maybe I'm speaking out of turn on this because I'm kind of. of starting to get into looking at this myself admittedly more than in the past. But that's just a tactic that's being used. So what's interesting about this is we see the big piece is actually a TDS being used, a traffic distribution system. So that is the starting point. That's what's embedded into these victim websites. And from there, we see it getting, you know, depending on
Starting point is 00:03:58 what the victim looks like, their browser, all these other things. That's where it's getting parsed to, you know, click fix or, you know, the fake updates to even like advertisement, different advertisement distributions. Well, let's talk about Drive Surge. What business are they actually in here? So we can't say for certain at the moment, but everything that we see and from, you know, kind of our past experiences, we believe this to be an, and, and, initial access broker. So that piece being more of the TDS system that's occurring. So we, again, believe that this group is they're the ones going out and compromising these websites, injecting their domains into it. And in the background, that's what's happening is we initially
Starting point is 00:04:50 see the TDS occurring. And from there, the victims are getting kind of pushed to different places. So the IAB part to us is the TDS system. And then it's almost like a pay per install or pay per, you know, victim to come our way. So we imagine, again, we haven't found 100% proof one or the other, but we imagine that, you know, someone comes and say, hey, I need victims that are using Chrome or I'm looking for people in this arena. But yeah, we just, we believe initial access brokers, you know, someone will come in and say, we need this type of person or we're looking for access in this area of the world or anything like that. You know, that traffic distribution system essentially can kind of help with that. People will click and they can see, oh, they're using this browser,
Starting point is 00:05:46 they're coming from here. And so that's where, that's how we see this working. Well, walk us through the victim journey, if you will. What happens when someone visits one of these compromised websites? Yeah, and I will say there's two victims really here, right? There's the compromised websites. Their sites are victimized of itself. Yeah. But yeah. So as a person browsing to the website, and that's another interesting thing is this is all happening in the background, the TDS system that's being used. You don't see it. You'll go to the website and you can browse. However, you know, in not have it. You have to really dig deep into the website code
Starting point is 00:06:26 to see it. So what's happening in the background is that TDS system is collecting all sorts of information about you and, you know, seeing where you're from, what kind of browser and all this stuff. And if you hit certain gates, you know, if you hit
Starting point is 00:06:42 certain criteria, then this TDS system will send you to wherever it is they have it set up. So it could send you to a certain click fix where you know, you get the pop-up saying, oh, your browser is out of date, download this. It could send you certain advertisements. So those are the different things we see.
Starting point is 00:07:03 And it could be certain people browse to these compromised websites, and they don't see anything at all because they don't hit the criteria that's being looked for. Now, what about the compromised websites themselves? How do they fall victim here? Well, I would say they're victim in that, you know, they're being used. In terms of, you know, they're, they're being compromised. Now, are they losing money? I don't know. I mean, at a certain point, it might be picked up that, hey, this isn't a great site to go to.
Starting point is 00:07:35 So this is, and I'll say, this is kind of me speculating. I haven't said this is exactly what's going on or we've seen it. But, you know, if you imagine, if you got these small businesses, they have their website. And at a certain point, someone's like, hey, if you go with this website, it's bad. you know, maybe it's being blocked somewhere and you're not getting visitors. You need that traffic, you know, for revenue or just get your name out there. So in the media, it's probably, I mean, they're victim because they're compromised, but does it hurt them in the media?
Starting point is 00:08:06 Probably not. But there could be consequences down the line. Yeah. One of the things that really struck me reading through the research was the scale of this operation. Can you share with us how extensive was this infrastructure? It's pretty big. So we right now, tracking, as of today, everything current, for example, we see 200 domains tied to this group across a number of different IP. So that's just today because we kind of look at everything going on right now. And then victim-wise, where, I mean, we're into the thousands. Probably I don't have the exact count. I would have to kind of go back and check, but well over 5,000, I would say victim, and I say victim websites. So it is pretty extensive.
Starting point is 00:08:58 We'll be right back. Great news. The federal EV rebate is back. Eligible customers get up to $5,000 with the federal EVAP rebate on select 2027 Volt and 2026 Equinox EV models. Visit your local Chevrolet dealer today for more details. My name is Peter Parker, but I'm also Spider-Man. This July, we're faced with a threat.
Starting point is 00:09:23 That can be anyone. The world may have. forgotten Peter Parker. I'm just a neighbor. Friendly neighbor. But he hasn't forgotten them. Sometimes Spider-Man has to do the hard thing. That's my responsibility.
Starting point is 00:09:35 Talk to Banner? I didn't know you could get that big. Spider-Man, brand new day. In theaters, July 31st. Hear that? It's your money calling. It wants a promotion. Elevate your savings with the Scotia
Starting point is 00:09:55 high-interest savings account. Always earn high regular interest rates that grow the more you save and invest. Conditions apply. Visit scotiabank.com slash h-I-SA to learn more. Scotia Bank. You're richer than you think. Organizations spend years building incident response plans,
Starting point is 00:10:20 but when a real crisis hits, many discover those plans were built for auditors, not for operating through disruption. We recently spoke with Courtney Gus, crisis management director at Sempris, about why true cyber resilience depends on more than compliance. She explains why organizations need to move beyond static playbooks, establish clear decision-making authority, and prepare leaders for the moments when technology and the plan itself may fail. If you're responsible for incident response, business continuity, or cyber resilience, this is a conversation you won't want to miss.
Starting point is 00:10:58 Listen to the full interview at explore.thecyberwire.com slash Sempris. Your team identified some technical fingerprints here that were associated with the infrastructure. Without getting too technical, what are some of the things that you all discovered? Yeah, so I think there's a few different areas we've gone through, and I think most probably anyone who's been an analyst will probably be shaking their head. Like, yep, get that. So, for example, some of these domains we're seeing with registration reuse of emails. So that tends to be a good pivot point.
Starting point is 00:11:47 But the other piece that we really, probably a lot of our fingerprints are actually on the delivery of the TDS, this particular TDS system going on. And we kind of look at things like the URL path that's picking up the resources, kind of uniquenesses in that. And then we're also looking at we found some for the malware for some pieces where it's delivering malware. we're able to fingerprint the servers for that as well as the actual TDS server. So the servers holding the TDS piece that's being served through the website. So we can kind of look at the different configurations on the server side to kind of pick up where that might be. What is your sense in terms of how long this operation has been operating? Have they been at this for a while?
Starting point is 00:12:39 based on the data a lot of it starts in January of this year so not very long we do see for some of more the back end servers we see it to go back to September of 2025 that said you know that kind of hints at it's they're newer wherever this group is newer you know i kind of caveat that with maybe they just switched infrastructures and we're just not seeing that connection farther back so Yeah, I guess I caveat a lot. I'm sorry about that. That's the nature of the beast, right? Right, right. So yeah, so we see, like I said, we see really this particular cluster looks very new. We haven't made any connections to history yet. So as of right now, you know, our best guest says they are new to the scene or this cluster is kind of newer until we, you know, discover otherwise.
Starting point is 00:13:35 Yeah. It strikes me that there's really two. stories here. There's there's the malware delivery techniques that you've outlined, but then also there's the industrialized infrastructure behind all of this. Like we're just talking about the scale of this. Do you think that's, that's accurate that these are both worth, these are both noteworthy? Oh yeah, definitely. I mean, just the scale. I think, and that's where, you know, kind of going back to we're thinking more of the IAB type group here on that scale. You know, they, that's their job, you know, going out and finding compromised web or vulnerable websites compromising. They're building up this infrastructure.
Starting point is 00:14:15 I think in general across a lot of these online criminal activities, they almost seem like a company in of themselves. So it's not surprising to see it at scale. And then from there, you know, they likely again theorizing these are IABs. That's their company. So they're gaining access. They need a big foothold to therefore have clients of their own, you know, coming in and paying them for access.
Starting point is 00:14:39 For the security folks in our audience, for the defenders out there, what should they be considering as a result of your research here? Are there any actionable lessons that they should take away? I don't know if there's anything new that we all haven't heard, you know. Yeah. You know, being safe on the internet. I think this is more towards the individuals, you know, don't go clicking on things. even if a pop-up comes up and says,
Starting point is 00:15:06 hey, you need to download this. Don't click yes. Don't, you know, always question everything. In terms of companies, I mean, it's hard. It's that cat-mouse game, you know, you're always trying to defend the best to do is just try to be aware, try to go out. I know I'm not supposed to pitch our stuff,
Starting point is 00:15:26 but not our stuff, but in general, you know, you've got a lot of people use the community of people finding these bad things because you can't do it alone either, I would say. You know, it's so big, we have to work together. So when you identify, hey, this is bad, we need to block this. You know, companies, you need to work on blocking what people have found. Oh, that's the best I could get for us.
Starting point is 00:15:52 Yeah, yeah. I mean, it sounds like there's definitely a, I guess, a security and awareness training sort of component to this, which comes with things like Click Fix. Yeah, exactly. Like I said, unfortunately, I think most of this is the end user for companies or people with their websites. You know, kind of be aware of what, you know, that it can happen. But I have a feeling a lot of these website, victim websites that we saw, usually they're not setting up their own servers. They have someone else doing it for them or they're using a service online, you know, to set up these websites. So it's just, it's hard to say, go out and look at your website and make sure, you know, it's not compromised.
Starting point is 00:16:38 It's hard to do that, I'm sure, on their own. But that is one way, you know, you at least have that in mind or I think companies need to be aware of that it's possible and probably hopefully go out and find resources for that. And then, yeah, the other side, you know, the people behind the computer clicking the mouse, you just, yeah, that awareness can't trust, pretty much can't trust almost. anything. You know, second guess, second, don't just jump right in. You know, always wonder why something's there or if something, you know, immediately pops up, say, well, why now? You know, close out and go look somewhere else and make sure that's what you really need. Our thanks to Lauren Fyveson from Silent Push for joining us, the research is titled Meet Drive Surge, a new threat actor using click-fix and fake update drive-by attacks in thousands of
Starting point is 00:17:37 We'll have a link in the show notes. That's Research Saturday, brought to you by N2K Cyberwire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the show notes or send an email to Cyberwire at n2K.com.
Starting point is 00:18:04 This episode was produced by Liz Stokes, where Mick, by Elliot Taltzman and Trey Hester. Our executive producer is Jennifer Ibin. Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here next time. Hey y'all, it's Kelly Clarkson with Wayfair.
Starting point is 00:18:34 Ever order furniture online and wonder, what if? Like, what if it doesn't hold up? That sofa was four days old. You should have ordered from Wayfair. With Wayfair, there's no what-if. Just style you love and quality you can trust. Visit Wayfair.ca.ca. Wayfair, every style, every home.
Starting point is 00:18:50 heading to this year's Black Hat USA, the N2K Cyberwire team will be on site recording from our podcast studio in the SpectorOps Kennel Club. If you're interested in joining us for a conversation or learning more about what we're recording throughout the week, visit sponsor.thecyberwire.com for more information. And make sure you stop by the studio and meet the N2K Cyberwire team. We'll see you there.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.