ForensicsS | Private Detective & Digital Forensics Investigation Experts
  • info@forensicss.com

    Send Email

  • 11400 West Olympic Blvd, Los Angeles, CA 90064

  • Home
  • About Us
  • Services
    • Domestic Investigation
      • Los Angeles Private Eye
      • Catch Cheater
      • Infidelity Investigations
      • Asset Investigations
      • Private Detective Orange County
      • Child Custody Investigations
      • Missing Person Locates
      • Wire Fraud
      • Corporate Security Investigations
      • Surveillance Operations
      • Financial Fraud Investigations
      • Bug Sweep TSCM Investigation
      • Workers Compensation Fraud Investigation
      • Asset and Hidden Finances Investigations
    • Cyber Security
      • DIGITAL EVIDENCE AUTHENTICATION
      • Cyber Bullying Online Investigation
      • Penetration Testing Service
      • Social Media Monitoring
      • Romance Scam Investigator
      • Cyber Stalking Investigation
      • Crypto Scam Investigation
      • Cyber Security Assessment
      • Cyber Harassment Online Investigator
      • Ransomware Attack Investigation
      • Social Media Investigator
      • Extortion Investigation services
      • Background Screening
      • Insurance Fraud Detective
      • Forensic Accounting
      • Online Identity Theft
      • Online Blackmail
      • Cell Phone Forensics
      • Automotive Forensics
      • Audio Video Forensics
      • E-Discovery
      • Assets Search 
      • Computer and Cell Phone Forensics
  • Closed Cases
    • Closed Cases
    • Case Details
  • News
  • Contact
310-270-0598

Confidentiality Guaranteed

310-270-0598

Confidentiality Guaranteed

Logo

Contact Info

  • 11400 West Olympic Blvd, Los Angeles, CA 90064
  • 310-270-0598
  • info@forensicss.com

    Blog Details

      ForensicsS | Private Detective & Digital Forensics Investigation Experts > News > Uncategorized > Hackers hijack thousands of websites for ClickFix and FakeUpdate assaults
    Hackers hijack thousands of websites for ClickFix and FakeUpdate assaults
    01
    Jun
    • ForensicsS
    • 0 Comments

    Hackers hijack thousands of websites for ClickFix and FakeUpdate assaults

    Identity theft

    identity theft Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

    A threat actor tracked as DriveSurge has been working mammoth-scale malware distribution campaigns using ClickFix and FakeUpdates ways on compromised websites.

    Hundreds of websites were compromised in DriveSurge campaigns to redirect company to malware-transport infrastructure, according to researchers at cybersecurity company SilentPush.

    ClickFix is a favored social engineering tactic that deceives victims into copying and executing malicious instructions on their systems, customarily ensuing in malware infections below the pretense of resolving a technical remark.

    identity theft image

    In FakeUpdates assaults, threat actors entice victims with incorrect tool update prompts, on the total impersonating browser updates, to trick them into downloading and placing in malicious payloads.

    In step with Quiet Push researchers, the DriveSurge threat actor essentially functions as an initial fetch entry to broker (IAB) working on a pay-per-set up (PPI) mannequin, enabling be conscious-on assaults.

    Guests of compromised websites are redirected by a Traffic Distribution System (TDS) identified as zTDS, which profiles them and determines whether or no longer a FakeUpdates or a ClickFix lure is more relevant.

    identity theft ClickFix example from the campaign
    ClickFix instance from the campaign
    Source: Quiet Push

    zTDS is an open-source TDS that has existed since no longer no longer as much as 2015 and that DriveSurge has been using since no longer no longer as much as September 2025.

    “The utilization of zTDS, DriveSurge hijacks thousands of legit, excessive-popularity websites and silently redirects company to malware, unbeknownst to the websites’ owners or their company,” Quiet Push says.

    The FakeUpdates lures gather bogus update notices for Chrome, Firefox, Edge, Safari, Opera, Plucky, Yandex, Vivaldi, Samsung Web, and UC Browser, while the ClickFix assaults gather PowerShell instructions.

    A case highlighted in the Quiet Push command involves a incorrect Firefox update that downloaded a ZIP archive containing multiple DLLs and a malicious executable named ‘Browser Replace.exe.’

    identity theft A fake update for Firefox
    A incorrect update for Firefox
    Source: Quiet Push

    The researchers identified eight technical fingerprints linked to the campaign that helped name DriveSurge infrastructure and compromised websites.

    Amongst them is a JavaScript injection following the ‘t.js?situation=’ pattern, the set < identification> is a definite price assigned to each compromised websites.

    By evaluation, Quiet Push stumbled on bigger than 80 malicious injection domains and a situation of pre-weaponized domains that had no longer yet been dilapidated in assaults.

    Moreover, the researchers stumbled on an obfuscated JavaScript payload particularly designed to present consideration to macOS desktop systems, delivered by verification-themed ClickFix assaults that hijack the clipboard, indicating that the campaign extends beyond Windows.

    Customers are instructed to fetch browser updates easiest from their app’s settings menu (About > Test for Updates) and to preserve away from executing instructions in the Windows uncover instructed or Terminal that they don’t fully realize.


    identity theft article image

    Identity theft

    The Validation Gap: Computerized Pentesting Solutions One Demand. You Want Six.

    Computerized pentesting tools command true price, nonetheless they were constructed to acknowledge to 1 ask: can an attacker transfer by the network? They weren’t constructed to confirm whether or no longer your controls block threats, your detection suggestions fireplace, or your cloud configs preserve.

    This recordsdata covers the 6 surfaces you positively bear to validate.

    Download Now

    Read More

    • Tags

    • cybercrime cybercrimefraud cybersecurity email-fraud forensics|digital-forensics hackers hijack Investigation malware online-scam online-scamphishing-attack private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker

    Recent Posts

    • FBI file finds funding scams surged 87% in two years
    • Can hackers pull your fingerprints from photos on social media?
    • Grey rhinos, unlit swans, and the kidnapping of Nancy Guthrie: What Company America nonetheless gets unfriendly about risk
    • Hackers hijack thousands of websites for ClickFix and FakeUpdate assaults
    • Right here’s Easy how to Offer protection to Yourself From This Subtle Signal Rip-off

    Recent Comments

    No comments to show.

    Categories

    • cybersecurity
    • Investigations
    • Uncategorized

    Recent Posts

    Can hackers pull your fingerprints from photos on social media?
    June 1, 2026
    Can hackers pull your fingerprints from photos on social media?
    Grey rhinos, unlit swans, and the kidnapping of Nancy Guthrie: What Company America nonetheless gets unfriendly about risk
    June 1, 2026
    Grey rhinos, unlit swans, and the kidnapping of Nancy Guthrie: What Company America nonetheless gets unfriendly about risk
    Hackers hijack thousands of websites for ClickFix and FakeUpdate assaults
    June 1, 2026
    Hackers hijack thousands of websites for ClickFix and FakeUpdate assaults

    Popular Tags

    administration Confirms Crypto cybercrime cybercrimefraud cybercrimehacker cybercrimephishing-attack cybersecurity Department digital-forensics director email-fraud Epstein forensics|digital-forensics Former fraud hacker hackers House Investigation investigationcybersecurity Judge Justice Launches malware malwarefraud malwarephishing-attack Microsoft Minnesota North online-scam online-scamphishing-attack opens Patel phishing-attack Police private-detective scam|fraud private-eye cyber|cybersecurity private-eye phishing|phishing-attack private-investigator private-investigator hacking|hacker probe Trump Trump’s warns

    Forensics – Trusted Experts in Surveillance, Cyber Security, Background Checks, and Digital Forensics across California.

    • 310-270-0598
    • info@forensicss.com
    • 11400 West Olympic Blvd, Los Angeles, CA 90064

    Explore

    • News
    • About
    • Our Services
    • Find A Person
    • Child Custody
    • Contact Us
    • Los Angeles
    • Orange County
    • San Diego

    Services

    • Cyber Security
    • Online Blackmail
    • Cell Phone Forensics
    • Domestic Investigation
    • Social Media Investigator
    • Crypto Scam Investigation

    Newsletter

    Sign up email to get our daily latest news & updates from us

    © Copyright 2021 by KRIGO