Thousands of compromised websites abused by DriveSurge in active ClickFix and FakeUpdates campaigns



  • SilentPush researchers uncovered DriveSurge, a large‑scale ClickFix campaign
  • Victims are profiled and served either ClickFix or FakeUpdates
  • Access is later sold on the dark web

An ongoing ClickFix campaign has infected thousands of computers with backdoor malware. This is according to security researchers SilentPush, who said the threat actors are selling the access on the dark web.

The campaign, dubbed DriveSurge, starts on poorly secured websites, where criminals inject malicious scripts. These scripts act as lightweight beacons, passing visitor data to a remote Traffic Distribution System (TDS) called zTDS. There, the visitors are evaluated and if deemed a target, the zTDS server instructs the script to load a ClickFix overlay.

https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img