A threat actor called DriveSurge has compromised thousands of legitimate websites to distribute malware via ClickFix and FakeUpdates social engineering tactics. Operating as an initial access broker on a pay-per-install model, DriveSurge uses the open-source zTDS traffic distribution system to profile visitors and serve tailored lures — fake browser update prompts (for Chrome, Firefox, Edge, and others) or PowerShell-based ClickFix attacks. Researchers at SilentPush identified over 80 malicious injection domains and a JavaScript fingerprint pattern used across compromised sites. The campaign also targets macOS via clipboard-hijacking ClickFix attacks, not just Windows. Users are advised to only update browsers through official in-app settings and avoid running unfamiliar terminal commands.