A new report covered by BleepingComputer highlights how a threat actor tracked as **DriveSurge** has been running large-scale malware distribution campaigns by compromising legitimate websites and using them to redirect visitors toward ClickFix and FakeUpdate attacks. According to researchers at Silent Push, thousands of websites have been hijacked and abused as part of this campaign, turning trusted web pages into delivery paths for malware. Because apparently even browsing a familiar-looking website now requires the suspicion level of airport security. 

This is not just another malware campaign. The dangerous part is the abuse of trust. Users are not landing on obviously suspicious websites. They may be visiting legitimate websites that have silently been compromised. From there, traffic is redirected through attacker-controlled infrastructure and profiled before the victim is shown the most suitable lure, such as a fake browser update or a fake technical fix. 

What Are ClickFix and FakeUpdate Attacks? 

ClickFix is a social engineering technique where victims are tricked into copying and executing malicious commands on their systems. The message usually pretends that the user needs to fix a browser issue, verification error, system problem, or access failure. In reality, the user is being persuaded to run the attacker’s payload manually. It is malware installation with extra steps, generously outsourced to the victim. 

FakeUpdate attacks use fraudulent software update prompts, often pretending to be updates for browsers such as Chrome, Firefox, Edge, Safari, Opera, Brave, and others. Users are made to believe they are installing a legitimate browser update, but they are actually downloading malware. In one case highlighted in the report, a fake Firefox update downloaded a ZIP file containing DLLs and a malicious executable named Browser Update.exe

Why This Campaign Is Serious 

The campaign is especially concerning because DriveSurge is reportedly operating as an initial access broker using a pay-per-install model. That means the objective may not always be the final attack. Instead, compromised systems can become entry points for other criminals, who may later deploy stealers, ransomware, remote access tools, or other malware. One group breaks the door, another walks in with a shopping list. Cybercrime, sadly, has discovered supply-chain efficiency. 

The report also mentions the use of a traffic distribution system called zTDS, which profiles visitors and decides whether to show a FakeUpdate lure or a ClickFix lure. This makes the campaign more adaptive because the attacker does not need to show every victim the same page. Different users, devices, browsers, or operating systems can receive different attack flows.

Silent Push researchers also found indicators such as JavaScript injection patterns, more than 80 malicious injection domains, and pre-weaponized domains that had not yet been used. The campaign also appears to extend beyond Windows, with researchers identifying an obfuscated JavaScript payload designed to target macOS desktop systems through verification-themed ClickFix attacks that hijack the clipboard. 

The Real Risk: Users Are Being Trained to Attack Themselves 

The most worrying part of ClickFix attacks is that they rely on user action. Instead of exploiting a vulnerability directly, attackers convince users to paste commands into PowerShell, Command Prompt, or Terminal. This bypasses many traditional expectations of security because the action appears to be initiated by the user.

That makes awareness critical. No website should ever ask a user to copy and run commands to fix a browser verification, update problem, CAPTCHA issue, or page loading error. A browser update should happen from the browser’s own settings menu or official update mechanism, not from a random pop-up wearing a fake badge and pretending to be helpful.

What End Users Should Do 

Users should avoid downloading browser updates from pop-ups, banners, or redirected pages. Browser updates should only be installed through the browser’s built-in update feature, such as the “About” or “Check for Updates” section, or from the official vendor website. 

Users should also treat any instruction to open PowerShell, Command Prompt, Terminal, or Run dialog and paste a command as highly suspicious. Legitimate websites do not need visitors to execute system commands to prove they are human. That is not verification. That is digital self-sabotage in a trench coat.

What Website Owners Should Do 

Website owners must treat website compromise as a serious security risk, even if the site does not store sensitive data. Many small businesses assume that because their website is only informational, attackers will not care. This campaign proves the opposite. Attackers do not always need your data. Sometimes they only need your reputation, domain authority, and visitor traffic.

Website owners should regularly patch CMS platforms, plugins, themes, JavaScript libraries, and admin panels. They should also monitor for unauthorized scripts, unexpected redirects, unfamiliar external domains, modified templates, suspicious JavaScript injections, and newly created admin accounts. Backups, file integrity monitoring, WAF rules, and secure admin access should not be treated as optional decorations.

What Organizations Should Learn 

For businesses, this incident reinforces the importance of layered security. Users may be exposed to these attacks while browsing legitimate websites, not just obviously malicious domains. Security teams should monitor DNS requests, web redirects, suspicious script loads, command execution patterns, and abnormal process chains such as browser-to-PowerShell or browser-to-Terminal activity.

Endpoint protection, DNS filtering, secure web gateways, browser isolation, user awareness, and threat intelligence all matter here. No single control can stop every attack, because attackers are using a mix of compromised infrastructure, social engineering, redirection systems, and payload delivery tricks. Naturally, they made it messy, because apparently clean attack chains were too kind.

Final Comment 

The DriveSurge campaign shows how attackers are abusing legitimate websites to make malware delivery look trustworthy. ClickFix and FakeUpdate attacks succeed because they exploit user trust, urgency, and confusion. A fake browser update or fake verification page may look harmless, but one copied command or downloaded “update” can be enough to compromise a system.

The key lesson is simple: trust should not be given to a web page just because the domain looks familiar. Website owners must secure and monitor their platforms, and users must be trained never to execute commands or install updates based on browser pop-ups or suspicious prompts.

Cybersecurity is no longer only about blocking bad websites. It is also about detecting when good websites have been turned bad. That is the uncomfortable little detail attackers are now exploiting at scale.


A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites. [...]

Source: Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks via Bleeping Computer — published 01 Jun 2026.