On hacked websites, a threat actor known as DriveSurge has been running extensive malware distribution operations employing ClickFix and FakeUpdates tactics.
Researchers at cybersecurity firm SilentPush claim that DriveSurge operations have infiltrated thousands of websites to reroute users to malware-delivery infrastructure.
Under the guise of fixing a technical problem, ClickFix is a common social engineering technique to trick victims into copying and running harmful commands on their systems, frequently leading to malware infestations.
Threat actors use phony software update prompts, typically posing as browser updates, to deceive users into downloading and installing malware payloads in FakeUpdates assaults.
The DriveSurge threat actor mainly serves as an initial access broker (IAB) using a pay-per-install (PPI) mechanism, allowing subsequent attacks, according to Silent Push researchers read more about Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
