Last seven days
- First activity
- Sep 7, 2026
- Last activity
- Sep 14, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 3509 hostnames
DriveSurge is a large-scale malware distribution threat cluster assessed to operate primarily as a specialized Initial Access Broker using a pay-per-install model.
Profile source: Mallory opens in a new tabDriveSurge
DriveSurge is a large-scale malware distribution threat cluster assessed to operate primarily as a specialized Initial Access Broker using a pay-per-install model. The actor compromises legitimate websites and injects malicious code that silently redirects visitors to attacker-controlled infrastructure, where victims are funneled into social-engineering-based malware delivery chains. Activity attributed to DriveSurge has been observed at global scale and has affected thousands of compromised websites.
DriveSurge is closely associated with two main delivery techniques: FakeUpdates and ClickFix. In FakeUpdates operations, the actor presents fraudulent browser update prompts that impersonate widely used browsers in order to trick users into downloading and executing malware. In ClickFix operations, the actor uses fake verification or error prompts to induce victims to paste attacker-supplied commands into PowerShell on Windows or Terminal on macOS, sometimes with clipboard hijacking to substitute malicious commands. The campaign has targeted both Windows and macOS users.
A defining feature of DriveSurge is its use of the open-source zTDS traffic distribution system to profile visitors and dynamically decide which lure, payload path, or redirect chain to serve. Reported infrastructure characteristics indicate a mature and resilient operation, including obfuscated JavaScript injects, API- or orchestrator-style delivery logic, failover mechanisms, and infrastructure patterns that support both active and pre-weaponized staging. The actor has also been linked to advertisement-style distribution components used to fingerprint visitors and verify human interaction before serving malicious content.
DriveSurge appears to focus on scalable initial access rather than publicly attributed hands-on-keyboard post-compromise operations. Its role is best understood as supplying downstream threat actors with victim access or installs rather than being tied to a single malware family. No high-confidence public attribution to a specific nation state is established in the available reporting. Known aliases are limited, and DriveSurge is the primary recognized name for this cluster.
C2 tracking
Derp observations, rolling seven-day window
Samples
04fe61a505bfea9cc2cec48c364606d227db80a0c689783670f427dab6c68299 1c816992aeebd39480cb9cdf25c007fbcffb08e665ec21941a516a4d45e16f55 1d846503289190d5d70e9a4df0a583fd4b171638daed8fe666995b5f8657032b 253dcadf7701082437820f33204f2a82b59f81aaec91382f21f47b0ac112189e 74591c297b87300ad88ad07463bb7cc0e17df6772e56dd9d6a87a3d815e30c81 6e0b2210a1b2b11c848fe38fbcdd6f2913e739d6eaf8c86721ed29585ab9003e 9cfbfa554400f8acc2585185ed4e09aeb4d8f5b5c43511eeb4a42834219b64e4 c13815258d726b167a8a6712aaebac759b9524bc30ba2515e5b0e5a87d757f1b 1d79627b49734bc8edff54d1197a55ae48370e23ab7385af29a9eeafe5d9adb7 78bc42a791847e7a859574e924d30533e0be4c6caa6ff67905230a0c07730cec MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.