Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors drivesurge

Also known as: tracked as, SHADOW-EARTH-053, Snappybee, TernDoor, MFA Fatigue, MFA Spamming

Description

DriveSurge is a newly identified large‑scale malware distribution threat cluster that leverages compromised websites to deliver attacker tools to high‑valued victims. The actor injects highly obfuscated JavaScript into legitimate web hosts, redirecting visitors through a Traffic Distribution System (zTDS) that forwards them to a library of malicious payloads. Two primary dissemination vectors are used: – **FakeUpdates** – the script presents fake browser update dialogs for popular browsers and other common software, prompting users to download and run counterfeit installers. – **ClickFix** – a social‑engineering trick that prompts users to execute malicious PowerShell commands hidden in a seemingly benign “fix” message. DriveSurge operates on a pay‑per‑install model: it sells the list of victims (identified by their unique file naming conventions and server fingerprints) to downstream threat actors who then deliver more sophisticated malware such as ROKRAT, ShadowPad or TernDoor. The infrastructure is robust; the actor utilizes bulletproof hosting providers, continuously rotates its domains (e.g., ztds.info, cptoptious.com, datumprobe.icu), and implements environment‑specific targeting including macOS systems. The group’s operational tempo has accelerated since at least September 2025, with daily injection campaigns affecting multiple sectors worldwide. The actor’s unique technical fingerprints—file suffixes such as ".update" and server configuration variables—enable detection and attribution when defensive teams inspect their own web assets. In addition to website hijacking, DriveSurge demonstrates advanced command‑and‑control capabilities by using zTDS to proxy traffic to its downstream payloads and employing PowerShell for local execution once a user’s browser has been deceived. The combination of low‑cost initial access, widespread delivery, and monetizable victim leads makes DriveSurge a potent threat to any organization with a public web presence.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Healthcare
Legal services
Manufacturing
Media
Energy
Education
Information technology
Telecommunications
Critical infrastructure
Transportation
Retail
Non profit
Oil gas
Utilities

Targeted Countries / Regions

CN
IR
KP
US
FR
PK
IL
AE
IN

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

DriveSurge is a financially‑motivated threat actor that hijacks thousands of public websites to host malicious JavaScript, redirecting visitors through its zTDS traffic distribution system and delivering malware via two main social‑engineering techniques: FakeUpdates (browser update prompts for Chrome, Firefox, Edge, Safari, etc.) and ClickFix (users are tricked into executing PowerShell commands). Operating as an Initial Access Broker with a pay‑per‑install model, DriveSurge sells victim leads to downstream actors such as ROKRAT or ShadowPad. The group targets many sectors—including finance, defense, government, healthcare, energy and more—across countries in the US, China, Iran, North Korea, UAE, India and others.

Goals & Targeting

DriveSurge is primarily driven by financial gain; it acts as an Initial Access Broker that supplies compromised accounts or infection vectors to downstream actors for further exploitation. The group targets multiple industries—including finance, defense, government, healthcare, legal services, manufacturing, energy, and telecom—because these sectors often contain valuable data or critical infrastructure assets and are more willing to pay for a proven foothold. By compromising high‑traffic public websites that serve global audiences, DriveSurge increases its reach across countries such as the US, China, Iran, North Korea, UAE, India and Pakistan. Victims tend to be medium‑to‑large enterprises that rely on web portals or corporate intranets accessible from the internet.

Enhanced Description

Key Capabilities

  • Website hijacking and JavaScript injection
  • Malicious redirect via zTDS traffic distribution system
  • FakeUpdates browser spoofing
  • ClickFix PowerShell command execution
  • Bulletproof hosting infrastructure
  • Obfuscated payload delivery
  • Unique file naming fingerprints for tracking
  • Pay‑per‑install business model to monetize victim leads

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Command and Control
Defense Evasion

ATT&CK Techniques

T1189 Drive-by Compromise
T1059.003 PowerShell
T1064 Scripting
T1071.001 Web Protocols
T1140 Deobfuscate/Decode Files or Information
T1086 Windows Command Shell
T1027 Hide Artifact (Obfuscated Files)

Software / Tooling

ROKRAT
ShadowPad
TernDoor
ClickFix Script
FakeUpdates Installer
PowerShell

Campaigns & Victims

DriveSurge’s campaigns are characterized by a high-volume, automated approach: thousands of compromised sites host identical JS snippets that redirect traffic to its proprietary C2. The act is highly modular—once a user visits the compromised site, the payload delivery is either a deceptive browser update prompt or a disguised PowerShell command. This allows DriveSurge to scale quickly while keeping operational costs low. The actor’s infrastructure shows rapid domain rotation and frequent exploitation of known vulnerabilities in public‑facing web servers. While the group has only been active since late 2025, its pay‑per‑install model has already attracted downstream monetization partners that distribute advanced RATs, spyware, or other backdoors on top of DriveSurge’s initial infection vector.

IOC Patterns

  • Drive-by attacks via compromised public websites using JavaScript redirects
  • Fake browser update prompts forcing users to download counterfeit installers
  • ClickFix technique prompting execution of malicious PowerShell scripts
  • Use of zTDS traffic distribution system for C2
  • Domain rotation among bulletproof hosting providers (e.g., ztds.info, datumprobe.icu),

Recommended Actions

  • Block known DriveSurge domains and IP ranges using threat‑intelligence feeds
  • Deploy a Web Application Firewall to detect and block injected malicious JavaScript on corporate sites
  • Monitor outbound HTTPS traffic for connections to zTDS or other known redirect services
  • Implement user education campaigns about fake browser updates and suspicious PowerShell prompts
  • Perform regular penetration testing of publicly exposed web servers for code injection vulnerabilities
  • Maintain up‑to‑date signature‑based scanners that flag unique DriveSurge file naming patterns
  • Configure DNS filtering to quarantine domains associated with the actor

Suggested Tags

APT
Malware Distribution
Initial Access Broker
Finance
Defense
Government
Healthcare
Energy
Telecommunications
Infrastructure-as-a-Service

Confidence Assessment

The majority of the information comes from public threat‑intelligence reports (SilentPush, Mallory.ai) and has been corroborated by multiple independent sources describing DriveSurge’s click‑fix and fake‑update campaigns. However, details about the actor’s internal organizational structure, exact financial model, and long‑term strategic intent are inferred rather than directly confirmed. The list of associated malware families is based on downstream actors likely to purchase leads from DriveSurge; direct attribution of those tools to DriveSurge remains uncertain. Additional up‑to‑date IOC feeds would improve confidence in real‑time detection.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 10 URL 4 Email Address 1 IPv4 Address 3 Filename 2

References

  1. www.darkowl.com — Cited by web research for: SHADOW-EARTH-053
  2. www.bleepingcomputer.com — Cited by web research for: Payload
  3. pmc.ncbi.nlm.nih.gov — Cited by web research for: Matrix
  4. www.silentpush.com — Cited by web research for: Bulletproof hosting
  5. https://www.silentpush.com/blog/drive-surge-clickfix-fakeupdates — Cited by AI analysis.
  6. https://mallory.ai/campaigns/DriveSurge — Cited by AI analysis.

Intel Summary

7

Techniques

45

Tools

0

Campaigns

45

IOCs

0

Observed Data

1

Tactics

Tags

APT
Initial Access Broker
Fraud/Financial Theft
Malware Distribution
Cybercriminals
Finance
Defense
Government
Healthcare
Energy
Telecommunications
Infrastructure-as-a-Service

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
Jul 5, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.