Also known as: tracked as, SHADOW-EARTH-053, Snappybee, TernDoor, MFA Fatigue, MFA Spamming
DriveSurge is a newly identified large‑scale malware distribution threat cluster that leverages compromised websites to deliver attacker tools to high‑valued victims. The actor injects highly obfuscated JavaScript into legitimate web hosts, redirecting visitors through a Traffic Distribution System (zTDS) that forwards them to a library of malicious payloads. Two primary dissemination vectors are used: – **FakeUpdates** – the script presents fake browser update dialogs for popular browsers and other common software, prompting users to download and run counterfeit installers. – **ClickFix** – a social‑engineering trick that prompts users to execute malicious PowerShell commands hidden in a seemingly benign “fix” message. DriveSurge operates on a pay‑per‑install model: it sells the list of victims (identified by their unique file naming conventions and server fingerprints) to downstream threat actors who then deliver more sophisticated malware such as ROKRAT, ShadowPad or TernDoor. The infrastructure is robust; the actor utilizes bulletproof hosting providers, continuously rotates its domains (e.g., ztds.info, cptoptious.com, datumprobe.icu), and implements environment‑specific targeting including macOS systems. The group’s operational tempo has accelerated since at least September 2025, with daily injection campaigns affecting multiple sectors worldwide. The actor’s unique technical fingerprints—file suffixes such as ".update" and server configuration variables—enable detection and attribution when defensive teams inspect their own web assets. In addition to website hijacking, DriveSurge demonstrates advanced command‑and‑control capabilities by using zTDS to proxy traffic to its downstream payloads and employing PowerShell for local execution once a user’s browser has been deceived. The combination of low‑cost initial access, widespread delivery, and monetizable victim leads makes DriveSurge a potent threat to any organization with a public web presence.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
DriveSurge is a financially‑motivated threat actor that hijacks thousands of public websites to host malicious JavaScript, redirecting visitors through its zTDS traffic distribution system and delivering malware via two main social‑engineering techniques: FakeUpdates (browser update prompts for Chrome, Firefox, Edge, Safari, etc.) and ClickFix (users are tricked into executing PowerShell commands). Operating as an Initial Access Broker with a pay‑per‑install model, DriveSurge sells victim leads to downstream actors such as ROKRAT or ShadowPad. The group targets many sectors—including finance, defense, government, healthcare, energy and more—across countries in the US, China, Iran, North Korea, UAE, India and others.
Goals & Targeting
DriveSurge is primarily driven by financial gain; it acts as an Initial Access Broker that supplies compromised accounts or infection vectors to downstream actors for further exploitation. The group targets multiple industries—including finance, defense, government, healthcare, legal services, manufacturing, energy, and telecom—because these sectors often contain valuable data or critical infrastructure assets and are more willing to pay for a proven foothold. By compromising high‑traffic public websites that serve global audiences, DriveSurge increases its reach across countries such as the US, China, Iran, North Korea, UAE, India and Pakistan. Victims tend to be medium‑to‑large enterprises that rely on web portals or corporate intranets accessible from the internet.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
DriveSurge’s campaigns are characterized by a high-volume, automated approach: thousands of compromised sites host identical JS snippets that redirect traffic to its proprietary C2. The act is highly modular—once a user visits the compromised site, the payload delivery is either a deceptive browser update prompt or a disguised PowerShell command. This allows DriveSurge to scale quickly while keeping operational costs low. The actor’s infrastructure shows rapid domain rotation and frequent exploitation of known vulnerabilities in public‑facing web servers. While the group has only been active since late 2025, its pay‑per‑install model has already attracted downstream monetization partners that distribute advanced RATs, spyware, or other backdoors on top of DriveSurge’s initial infection vector.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The majority of the information comes from public threat‑intelligence reports (SilentPush, Mallory.ai) and has been corroborated by multiple independent sources describing DriveSurge’s click‑fix and fake‑update campaigns. However, details about the actor’s internal organizational structure, exact financial model, and long‑term strategic intent are inferred rather than directly confirmed. The list of associated malware families is based on downstream actors likely to purchase leads from DriveSurge; direct attribution of those tools to DriveSurge remains uncertain. Additional up‑to‑date IOC feeds would improve confidence in real‑time detection.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
45
Tools
0
Campaigns
45
IOCs
0
Observed Data
1
Tactics