discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

SilentPush says DriveSurge has compromised thousands of sites to push ClickFix and FakeUpdates lures that deliver malware to visitors.

By Bill Toulas·Jun 1·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
Image: bleepingcomputer.com

SilentPush says the DriveSurge threat actor is using hijacked, high-reputation websites and a traffic system called zTDS to steer visitors into malware-delivery pages. The campaign mixes fake browser-update prompts and ClickFix-style command tricks, and it reaches beyond Windows to macOS.

Why it matters

This is a large-scale web compromise and social-engineering campaign, not a single-site incident. It shows how attackers combine trusted websites, traffic profiling, and fake updates to spread malware at scale.

A group of hackers has been sneaking bad code onto many real websites. When people visit those sites, they get sent to fake pages that try to trick them into installing malware.

It is a bit like a street sign that looks normal but secretly points drivers into a trap. Some of the fake pages say a browser needs an update, and others try to make people copy and paste harmful commands.

The big lesson is to only update a browser from its own settings. Random pop-ups and strange command prompts are not safe helpers; they are part of the trick.

Analysis

What SilentPush found

SilentPush says the DriveSurge threat actor has been running large malware-distribution campaigns through compromised websites. The group has reportedly taken over thousands of sites and used them to redirect visitors into malware-delivery infrastructure without the site owners or visitors noticing.

How the attacks work

The campaign uses two common lures. One is ClickFix, where victims are persuaded to copy and run commands that appear to solve a technical problem. The other is FakeUpdates, which shows bogus browser update prompts to push malware downloads. SilentPush says DriveSurge uses an open-source traffic distribution system called zTDS to profile visitors and decide which lure to present.

The fake update prompts imitate Chrome, Firefox, Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, and UC Browser. In one example described in the report, a fake Firefox update led to a ZIP file containing several DLLs and a malicious executable named Browser Update.exe.

Technical clues and scope

Researchers identified eight technical fingerprints tied to the campaign, including a JavaScript injection pattern of t.js?site=<id>, where each compromised website gets a unique identifier. SilentPush says it found more than 80 malicious injection domains, plus additional pre-weaponized domains that had not yet been used.

The report also says the campaign is not limited to Windows. SilentPush found an obfuscated JavaScript payload aimed at macOS desktops, delivered through verification-themed ClickFix pages that hijack the clipboard. The practical takeaway is simple: browser updates should come from the browser’s own settings, and users should avoid running commands they do not understand.

Key points

  • SilentPush says DriveSurge has compromised thousands of websites for malware delivery.
  • The campaign uses ClickFix command-copy tricks and fake browser update prompts.
  • A traffic system called zTDS helps choose which lure to show each visitor.
  • Researchers found more than 80 malicious injection domains and other unused infrastructure.
  • The campaign includes a macOS-targeting payload, not just Windows attacks.
The Upside

The report gives defenders concrete fingerprints, including injection patterns and domain infrastructure, that can help them find compromised sites faster. It also reinforces a simple user defense: browser updates should come from the browser itself, which could reduce successful infections if widely followed.

The Downside

The campaign already spans thousands of sites, which means many users could be exposed before defenders clean it up. Because the lure adapts to the visitor and now targets macOS as well as Windows, the attack surface is broader than a single-platform phishing campaign.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymalwaresocial-engineeringcybercrimemacoswindows

Author

Bill Toulas

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 1, 2026

Source

bleepingcomputer.com

Share

Topics

securitymalwaresocial-engineeringcybercrimemacoswindows

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…