A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites

Reported 30 May 2026 by otx · Severity: medium

DriveSurge is a newly identified threat actor operating as an Initial Access Broker using a Pay-Per-Install model to supply victim leads to downstream actors. The actor has compromised thousands of websites, injecting malicious code that redirects visitors through zTDS (Traffic D