CyberWire Daily - When trusted sites turn. [Research Saturday]
Episode Date: July 18, 2026Lauren Fievisohn, Ph.D, Senior Threat Researcher from Silent Push, is sharing their work on "Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Comprom...ised Sites." Silent Push researchers have identified a newly named threat actor, DriveSurge, which has compromised thousands of legitimate websites and uses ClickFix and fake browser update lures to distribute malware at scale through a pay-per-install operation. The group leverages a traffic distribution system called zTDS to silently redirect visitors from trusted websites to malicious payloads, while employing sophisticated infrastructure, obfuscation, and fingerprinting techniques to evade detection. The report also details how DriveSurge targets both Windows and macOS users and provides defenders with eight infrastructure fingerprints to help identify and disrupt the campaign. The research and executive brief can be found here: Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites Learn more about your ad choices. Visit megaphone.fm/adchoices
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
This episode is brought to you by Accenture.
When your advertising operations fall out of sync, everything else follows.
Spotify and Accenture are working together to reinvent the rhythm of ad sales,
using automation, analytics, and smarter workflows to simplify campaign delivery
and access better data across the business.
The result?
Less time spent on operations, more time connecting brands with the moments and fandums
that matter most. Learn more at Accenture.com slash Spotify.
This episode is supported by Black Hat USA. If you follow the research, you know a lot of it breaks
on Black Hat stages. Hundreds of peer-reviewed briefings, more than 100 hands-on trainings,
and the largest business hall in Black Hat's history. Six days to learn the skills you'll need
tomorrow. August 1st to the 6th. Prices increased July 17th, so book before then. Use code
Cyberwire for $200 off your briefing pass at blackhat.com. We'll see you in Vegas.
Hello everyone and welcome to the CyberWire's Research Saturday. I'm Dave Bittner and this is our
weekly conversation with researchers and analysts tracking down the threats and vulnerabilities,
solving some of the hard problems and protecting ourselves in a rapidly evolving cyberspace.
Thanks for joining us. This M1 in particular,
It pulled from two different places.
So one is bulletproof hosting providers, particularly one of our recent or past white papers.
We've identified Nicnick as a bulletproof hosting provider.
So we have that on the one end.
And then on the other side, just kind of this idea of, okay, what are general behaviors of bad, you know?
So that's the other side.
So we were thinking, okay, let's look at everything that's hosted on NiceNick.
and then looking to see of those domains, which ones are providing resources to websites.
And through that, you know, kind of looking at these behaviors, we found this big cluster that we have said is drive surge.
That's Lauren Fivison, senior threat researcher from Silent Push.
The research we're discussing today is titled Meet Drive Surge, a new threat actor using click-fix and fake update drive-by attacks in thousands of compromise sites.
So I think probably most of our listeners are familiar with things like click fix and fake updates.
At what point did this activity stop looking like them and start looking like its own coordinated operation?
So the interesting thing, and so I'd say like click fix and fake updates, I won't say it's a group.
And maybe I'm speaking out of turn on this because I'm kind of.
of starting to get into looking at this myself admittedly more than in the past.
But that's just a tactic that's being used.
So what's interesting about this is we see the big piece is actually a TDS being used,
a traffic distribution system.
So that is the starting point.
That's what's embedded into these victim websites.
And from there, we see it getting, you know, depending on
what the victim looks like, their browser, all these other things. That's where it's getting
parsed to, you know, click fix or, you know, the fake updates to even like advertisement, different
advertisement distributions. Well, let's talk about Drive Surge. What business are they actually in here?
So we can't say for certain at the moment, but everything that we see and from, you know,
kind of our past experiences, we believe this to be an, and, and,
initial access broker. So that piece being more of the TDS system that's occurring. So we,
again, believe that this group is they're the ones going out and compromising these websites,
injecting their domains into it. And in the background, that's what's happening is we initially
see the TDS occurring. And from there, the victims are getting kind of pushed to different
places. So the IAB part to us is the TDS system. And then it's almost like a pay per install
or pay per, you know, victim to come our way. So we imagine, again, we haven't found 100% proof one
or the other, but we imagine that, you know, someone comes and say, hey, I need victims that are
using Chrome or I'm looking for people in this arena. But yeah, we just, we believe initial access brokers,
you know, someone will come in and say, we need this type of person or we're looking for access
in this area of the world or anything like that. You know, that traffic distribution system essentially
can kind of help with that. People will click and they can see, oh, they're using this browser,
they're coming from here. And so that's where, that's how we see this working. Well, walk us through the
victim journey, if you will. What happens when someone visits one of these compromised websites?
Yeah, and I will say there's two victims really here, right? There's the compromised websites.
Their sites are victimized of itself. Yeah. But yeah. So as a person browsing to the website,
and that's another interesting thing is this is all happening in the background, the TDS system that's being
used. You don't see it. You'll go to the website and you can browse. However, you know, in not
have it. You have to really dig
deep into the website code
to see it. So what's happening in
the background is that TDS
system is collecting all sorts of
information about you
and, you know, seeing where you're from,
what kind of browser and all this stuff.
And if you hit
certain gates, you know, if you hit
certain criteria,
then this TDS system will
send you to wherever it is
they have it set up. So it could send you
to a certain click fix where
you know, you get the pop-up saying, oh, your browser is out of date, download this.
It could send you certain advertisements.
So those are the different things we see.
And it could be certain people browse to these compromised websites, and they don't see anything at all because they don't hit the criteria that's being looked for.
Now, what about the compromised websites themselves?
How do they fall victim here?
Well, I would say they're victim in that, you know, they're being used.
In terms of, you know, they're, they're being compromised.
Now, are they losing money?
I don't know.
I mean, at a certain point, it might be picked up that, hey, this isn't a great site to go to.
So this is, and I'll say, this is kind of me speculating.
I haven't said this is exactly what's going on or we've seen it.
But, you know, if you imagine, if you got these small businesses, they have their website.
And at a certain point, someone's like, hey, if you go with this website, it's bad.
you know, maybe it's being blocked somewhere and you're not getting visitors.
You need that traffic, you know, for revenue or just get your name out there.
So in the media, it's probably, I mean, they're victim because they're compromised,
but does it hurt them in the media?
Probably not.
But there could be consequences down the line.
Yeah.
One of the things that really struck me reading through the research was the scale of this
operation.
Can you share with us how extensive was this infrastructure?
It's pretty big. So we right now, tracking, as of today, everything current, for example, we see 200 domains tied to this group across a number of different IP. So that's just today because we kind of look at everything going on right now. And then victim-wise, where, I mean, we're into the thousands. Probably I don't have the exact count. I would have to kind of go back and check, but well over 5,000, I would say victim, and I say victim websites.
So it is pretty extensive.
We'll be right back.
Great news.
The federal EV rebate is back.
Eligible customers get up to $5,000 with the federal EVAP rebate on select 2027
Volt and 2026 Equinox EV models.
Visit your local Chevrolet dealer today for more details.
My name is Peter Parker, but I'm also Spider-Man.
This July, we're faced with a threat.
That can be anyone.
The world may have.
forgotten Peter Parker.
I'm just a neighbor.
Friendly neighbor.
But he hasn't forgotten them.
Sometimes Spider-Man has to do the hard thing.
That's my responsibility.
Talk to Banner?
I didn't know you could get that big.
Spider-Man, brand new day.
In theaters, July 31st.
Hear that?
It's your money calling.
It wants a promotion.
Elevate your savings with the Scotia
high-interest savings account.
Always earn high regular interest rates
that grow the more you save and invest.
Conditions apply.
Visit scotiabank.com slash h-I-SA to learn more.
Scotia Bank.
You're richer than you think.
Organizations spend years building incident response plans,
but when a real crisis hits,
many discover those plans were built for auditors,
not for operating through disruption.
We recently spoke with Courtney Gus,
crisis management director at Sempris,
about why true cyber resilience depends on more than compliance.
She explains why organizations need to move beyond static playbooks, establish clear decision-making authority, and prepare leaders for the moments when technology and the plan itself may fail.
If you're responsible for incident response, business continuity, or cyber resilience, this is a conversation you won't want to miss.
Listen to the full interview at explore.thecyberwire.com slash Sempris.
Your team identified some technical fingerprints here that were associated with the infrastructure.
Without getting too technical, what are some of the things that you all discovered?
Yeah, so I think there's a few different areas we've gone through,
and I think most probably anyone who's been an analyst will probably be shaking their head.
Like, yep, get that.
So, for example, some of these domains we're seeing with registration reuse of emails.
So that tends to be a good pivot point.
But the other piece that we really, probably a lot of our fingerprints are actually on the delivery of the TDS, this particular TDS system going on.
And we kind of look at things like the URL path that's picking up the resources, kind of uniquenesses in that.
And then we're also looking at we found some for the malware for some pieces where it's delivering malware.
we're able to fingerprint the servers for that as well as the actual TDS server.
So the servers holding the TDS piece that's being served through the website.
So we can kind of look at the different configurations on the server side to kind of pick up where that might be.
What is your sense in terms of how long this operation has been operating?
Have they been at this for a while?
based on the data a lot of it starts in January of this year so not very long we do see for some of
more the back end servers we see it to go back to September of 2025 that said you know that
kind of hints at it's they're newer wherever this group is newer you know i kind of caveat that with
maybe they just switched infrastructures and we're just not seeing that connection farther back so
Yeah, I guess I caveat a lot. I'm sorry about that.
That's the nature of the beast, right?
Right, right. So yeah, so we see, like I said, we see really this particular cluster looks very new.
We haven't made any connections to history yet. So as of right now, you know, our best guest says they are new to the scene or this cluster is kind of newer until we, you know, discover otherwise.
Yeah. It strikes me that there's really two.
stories here. There's there's the malware delivery techniques that you've outlined, but then also
there's the industrialized infrastructure behind all of this. Like we're just talking about the scale
of this. Do you think that's, that's accurate that these are both worth, these are both noteworthy?
Oh yeah, definitely. I mean, just the scale. I think, and that's where, you know, kind of going back to
we're thinking more of the IAB type group here on that scale. You know, they, that's their job, you know,
going out and finding compromised web or vulnerable websites compromising.
They're building up this infrastructure.
I think in general across a lot of these online criminal activities,
they almost seem like a company in of themselves.
So it's not surprising to see it at scale.
And then from there, you know, they likely again theorizing these are IABs.
That's their company.
So they're gaining access.
They need a big foothold to therefore have clients of their own, you know,
coming in and paying them for access.
For the security folks in our audience, for the defenders out there, what should they be considering
as a result of your research here?
Are there any actionable lessons that they should take away?
I don't know if there's anything new that we all haven't heard, you know.
Yeah.
You know, being safe on the internet.
I think this is more towards the individuals, you know, don't go clicking on things.
even if a pop-up comes up and says,
hey, you need to download this.
Don't click yes.
Don't, you know, always question everything.
In terms of companies, I mean, it's hard.
It's that cat-mouse game, you know,
you're always trying to defend the best to do is just try to be aware,
try to go out.
I know I'm not supposed to pitch our stuff,
but not our stuff,
but in general, you know,
you've got a lot of people use the community of people finding these bad things
because you can't do it alone either, I would say.
You know, it's so big, we have to work together.
So when you identify, hey, this is bad, we need to block this.
You know, companies, you need to work on blocking what people have found.
Oh, that's the best I could get for us.
Yeah, yeah.
I mean, it sounds like there's definitely a, I guess, a security and awareness training sort of component to this, which comes with things like Click Fix.
Yeah, exactly.
Like I said, unfortunately, I think most of this is the end user for companies or people with their websites.
You know, kind of be aware of what, you know, that it can happen.
But I have a feeling a lot of these website, victim websites that we saw, usually they're not setting up their own servers.
They have someone else doing it for them or they're using a service online, you know, to set up these websites.
So it's just, it's hard to say, go out and look at your website and make sure, you know, it's not compromised.
It's hard to do that, I'm sure, on their own.
But that is one way, you know, you at least have that in mind or I think companies need to be aware of that it's possible and probably hopefully go out and find resources for that.
And then, yeah, the other side, you know, the people behind the computer clicking the mouse, you just, yeah, that awareness can't trust, pretty much can't trust almost.
anything. You know, second guess, second, don't just jump right in. You know, always wonder why
something's there or if something, you know, immediately pops up, say, well, why now? You know,
close out and go look somewhere else and make sure that's what you really need.
Our thanks to Lauren Fyveson from Silent Push for joining us, the research is titled Meet
Drive Surge, a new threat actor using click-fix and fake update drive-by attacks in thousands of
We'll have a link in the show notes.
That's Research Saturday, brought to you by N2K Cyberwire.
We'd love to know what you think of this podcast.
Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly
changing world of cybersecurity.
If you like our show, please share a rating and review in your favorite podcast app.
Please also fill out the survey in the show notes or send an email to Cyberwire at
n2K.com.
This episode was produced by Liz Stokes, where Mick,
by Elliot Taltzman and Trey Hester.
Our executive producer is Jennifer Ibin.
Peter Kilpe is our publisher,
and I'm Dave Bittner.
Thanks for listening.
We'll see you back here next time.
Hey y'all, it's Kelly Clarkson with Wayfair.
Ever order furniture online and wonder, what if?
Like, what if it doesn't hold up?
That sofa was four days old.
You should have ordered from Wayfair.
With Wayfair, there's no what-if.
Just style you love and quality you can trust.
Visit Wayfair.ca.ca.
Wayfair, every style, every home.
heading to this year's Black Hat USA, the N2K Cyberwire team will be on site recording from our podcast studio in the SpectorOps Kennel Club.
If you're interested in joining us for a conversation or learning more about what we're recording throughout the week,
visit sponsor.thecyberwire.com for more information.
And make sure you stop by the studio and meet the N2K Cyberwire team.
We'll see you there.
