Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    CVE-2026-8293 | THREATINT

    June 2, 2026

    Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

    June 2, 2026

    SSA-321292 V1.6 (Last Update: 2024-10-08): Denial of Service in the OPC Foundation Local Discovery Server (LDS) in Industrial Products

    June 2, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
    News

    Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

    adminBy adminJune 2, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

    A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites.

    Thousands of websites have been compromised in DriveSurge campaigns to redirect visitors to malware-delivery infrastructure, according to researchers at cybersecurity company SilentPush.

    ClickFix is a popular social engineering tactic that deceives victims into copying and executing malicious commands on their systems, often resulting in malware infections under the pretense of resolving a technical issue.

    image

    In FakeUpdates attacks, threat actors entice victims with fraudulent software update prompts, usually impersonating browser updates, to trick them into downloading and installing malicious payloads.

    According to Silent Push researchers, the DriveSurge threat actor primarily functions as an initial access broker (IAB) operating on a pay-per-install (PPI) model, enabling follow-on attacks.

    Visitors of compromised websites are redirected through a Traffic Distribution System (TDS) known as zTDS, which profiles them and determines whether a FakeUpdates or a ClickFix lure is more appropriate.

    ClickFix example from the campaign
    ClickFix example from the campaign
    Source: Silent Push

    zTDS is an open-source TDS that has existed since at least 2015 and that DriveSurge has been using since at least September 2025.

    “Using zTDS, DriveSurge hijacks thousands of legitimate, high-reputation websites and silently redirects visitors to malware, unbeknownst to the sites’ owners or their visitors,” Silent Push says.

    The FakeUpdates lures contain bogus update notices for Chrome, Firefox, Edge, Safari, Opera, Brave, Yandex, Vivaldi, Samsung Internet, and UC Browser, while the ClickFix attacks involve PowerShell commands.

    A case highlighted in the Silent Push report involves a fake Firefox update that downloaded a ZIP archive containing multiple DLLs and a malicious executable named ‘Browser Update.exe.’

    A fake update for Firefox
    A fake update for Firefox
    Source: Silent Push

    The researchers identified eight technical fingerprints linked to the campaign that helped identify DriveSurge infrastructure and compromised websites.

    Among them is a JavaScript injection following the ‘t.js?site=’ pattern, where < id> is a unique value assigned to each compromised website.

    Through analysis, Silent Push discovered more than 80 malicious injection domains and a set of pre-weaponized domains that had not yet been used in attacks.

    Additionally, the researchers discovered an obfuscated JavaScript payload specifically designed to target macOS desktop systems, delivered via verification-themed ClickFix attacks that hijack the clipboard, indicating that the campaign extends beyond Windows.

    Users are recommended to download browser updates only from their app’s settings menu (About > Check for Updates) and to avoid executing commands in the Windows command prompt or Terminal that they don’t fully understand.


    article image

    Automated pentesting tools deliver real value, but they were built to answer one question: can an attacker move through the network? They were not built to test whether your controls block threats, your detection rules fire, or your cloud configs hold.

    This guide covers the 6 surfaces you actually need to validate.

    Download Now



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSSA-321292 V1.6 (Last Update: 2024-10-08): Denial of Service in the OPC Foundation Local Discovery Server (LDS) in Industrial Products
    Next Article CVE-2026-8293 | THREATINT
    admin
    • Website

    Related Posts

    News

    AI Grifters Are Making Anti-Data Center Slop With AI

    June 1, 2026
    News

    We Sued ICE to Get Its Spyware Contract. The Agency Is Redacting Essentially Everything

    June 1, 2026
    News

    Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked

    June 1, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views

    The Essential Guide to Removing Computer Infections: Step-by-Step Remedies

    March 20, 202627 Views
    Our Picks

    CVE-2026-8293 | THREATINT

    June 2, 2026

    Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

    June 2, 2026

    SSA-321292 V1.6 (Last Update: 2024-10-08): Denial of Service in the OPC Foundation Local Discovery Server (LDS) in Industrial Products

    June 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.