Skip to content

DriveSurge

DriveSurge is a large-scale malware distribution threat cluster assessed to operate primarily as a specialized Initial Access Broker using a pay-per-install model.

Profile source: Mallory opens in a new tab

DriveSurge

Family profile

DriveSurge is a large-scale malware distribution threat cluster assessed to operate primarily as a specialized Initial Access Broker using a pay-per-install model. The actor compromises legitimate websites and injects malicious code that silently redirects visitors to attacker-controlled infrastructure, where victims are funneled into social-engineering-based malware delivery chains. Activity attributed to DriveSurge has been observed at global scale and has affected thousands of compromised websites.

DriveSurge is closely associated with two main delivery techniques: FakeUpdates and ClickFix. In FakeUpdates operations, the actor presents fraudulent browser update prompts that impersonate widely used browsers in order to trick users into downloading and executing malware. In ClickFix operations, the actor uses fake verification or error prompts to induce victims to paste attacker-supplied commands into PowerShell on Windows or Terminal on macOS, sometimes with clipboard hijacking to substitute malicious commands. The campaign has targeted both Windows and macOS users.

A defining feature of DriveSurge is its use of the open-source zTDS traffic distribution system to profile visitors and dynamically decide which lure, payload path, or redirect chain to serve. Reported infrastructure characteristics indicate a mature and resilient operation, including obfuscated JavaScript injects, API- or orchestrator-style delivery logic, failover mechanisms, and infrastructure patterns that support both active and pre-weaponized staging. The actor has also been linked to advertisement-style distribution components used to fingerprint visitors and verify human interaction before serving malicious content.

DriveSurge appears to focus on scalable initial access rather than publicly attributed hands-on-keyboard post-compromise operations. Its role is best understood as supplying downstream threat actors with victim access or installs rather than being tied to a single malware family. No high-confidence public attribution to a specific nation state is established in the available reporting. Known aliases are limited, and DriveSurge is the primary recognized name for this cluster.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 30, 2026
Last activity
Jul 30, 2026
Feed role
C2 / Distribution
Host form
0 IP / 1381 hostnames

Leading locations

  • US616
  • FR92
  • DE91
  • BR69
  • NL57
  • GB37
  • IN34
  • FI30
  • RU24
  • SG24
  • CA23
  • IT23

Leading providers

  • Hostinger International Limited124
  • Cloudflare, Inc.107
  • Oracle Corporation90
  • Cloudflare London, LLC79
  • OVH SAS56
  • Namecheap, Inc.51

Infrastructure traits

  • Hosting 1300
  • Anycast 354
  • Proxy 76
  • Vpn 11

MITRE ATT&CK

DriveSurge in ATT&CK

20 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.