Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
SilentPush says DriveSurge has compromised thousands of sites to push ClickFix and FakeUpdates lures that deliver malware to visitors.
Intelligence analysis by GPT-5.4 Mini

SilentPush says the DriveSurge threat actor is using hijacked, high-reputation websites and a traffic system called zTDS to steer visitors into malware-delivery pages. The campaign mixes fake browser-update prompts and ClickFix-style command tricks, and it reaches beyond Windows to macOS.
A group of hackers has been sneaking bad code onto many real websites. When people visit those sites, they get sent to fake pages that try to trick them into installing malware.
It is a bit like a street sign that looks normal but secretly points drivers into a trap. Some of the fake pages say a browser needs an update, and others try to make people copy and paste harmful commands.
The big lesson is to only update a browser from its own settings. Random pop-ups and strange command prompts are not safe helpers; they are part of the trick.
Analysis
What SilentPush found
SilentPush says the DriveSurge threat actor has been running large malware-distribution campaigns through compromised websites. The group has reportedly taken over thousands of sites and used them to redirect visitors into malware-delivery infrastructure without the site owners or visitors noticing.
How the attacks work
The campaign uses two common lures. One is ClickFix, where victims are persuaded to copy and run commands that appear to solve a technical problem. The other is FakeUpdates, which shows bogus browser update prompts to push malware downloads. SilentPush says DriveSurge uses an open-source traffic distribution system called zTDS to profile visitors and decide which lure to present.
The fake update prompts imitate Chrome, Firefox, Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, and UC Browser. In one example described in the report, a fake Firefox update led to a ZIP file containing several DLLs and a malicious executable named Browser Update.exe.
Technical clues and scope
Researchers identified eight technical fingerprints tied to the campaign, including a JavaScript injection pattern of t.js?site=<id>, where each compromised website gets a unique identifier. SilentPush says it found more than 80 malicious injection domains, plus additional pre-weaponized domains that had not yet been used.
The report also says the campaign is not limited to Windows. SilentPush found an obfuscated JavaScript payload aimed at macOS desktops, delivered through verification-themed ClickFix pages that hijack the clipboard. The practical takeaway is simple: browser updates should come from the browser’s own settings, and users should avoid running commands they do not understand.
Key points
- SilentPush says DriveSurge has compromised thousands of websites for malware delivery.
- The campaign uses ClickFix command-copy tricks and fake browser update prompts.
- A traffic system called zTDS helps choose which lure to show each visitor.
- Researchers found more than 80 malicious injection domains and other unused infrastructure.
- The campaign includes a macOS-targeting payload, not just Windows attacks.
The report gives defenders concrete fingerprints, including injection patterns and domain infrastructure, that can help them find compromised sites faster. It also reinforces a simple user defense: browser updates should come from the browser itself, which could reduce successful infections if widely followed.
The campaign already spans thousands of sites, which means many users could be exposed before defenders clean it up. Because the lure adapts to the visitor and now targets macOS as well as Windows, the attack surface is broader than a single-platform phishing campaign.



