DriveSurgeDriveSurge

Also known as: DriveSurge

Known aliases
1

Profile

DriveSurge compromises legitimate websites to inject scripts that route visitors through zTDS, leading them to fake browser updates and ClickFix-style prompts. This operation resembles an initial-access broker model, where successful infections generate leads for downstream threat actors. The actor employs tactics that avoid detection by site administrators, allowing infections to go unnoticed during routine checks.

Aliases· 1

DriveSurge

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Technique
Drive-by Compromise
Software
FakeUpdates
Actor
GURU SPIDER
Actor
TINY SPIDER
Actor
GOLD PRELUDE
Actor
EvilTraffic
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.