Loading summary
Host/Announcer
You're listening to the Cyberwire Network powered by N2K.
Advertiser/Commercial Voice
Are all batteries the same? That's like asking if all soccer players are the same. Take Messi, the most decorated player ever. Is there any other player who has achieved that? No, just him. Now take Duracell. Is there any other battery with power boost ingredients inside? No, just Duracell. Remember, goats only trust goats because they're built different. And Messi only trusts Duracell.
Dave Bitt
This episode is supported by Black Hat usa. If you follow the research, you know a lot of it breaks on. Black Hat stages hundreds of peer reviewed briefings, more than 100 hands on trainings, and the largest business hall in Black Hat's history. Six days to learn the skills you'll need tomorrow August 1st to the 6th. Prices increase July 17th, so book before then. Use code CYBERWIRE for $200 off your briefing pass@BlackHat.com we'll see you in Vegas. Hello everyone and welcome to the Cyberwires Research Saturday. I'm Dave Bitt and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems and protecting ourselves in our rapidly evolving cyberspace. Thanks for joining us.
Lauren Fevason
This M1 in particular, it pulled from two different places. So one is bulletproof hosting providers. Particularly one of our recent or past white papers, we've identified Nicenic as a bulletproof hosting provider. So we have that on the one end and then on the other side just kind of this idea of okay, what are general behaviors of bad, you know, so that's the other side. So we were thinking, okay, let's look at everything that's hosted on Nicenic and then looking to see of those domains which ones are providing resources to websites. And through that, you know, kind of looking at these behaviors, we found this big cluster that we have said is drive Surge.
Dave Bitt
That's Lauren Fevason, senior threat researcher from Silent Push. The research we're discussing today is titled Meet Drive Surge a new threat actor using click fix and fake update drive by attacks in thousands of compromised sites. So I think probably, probably most of our listeners are familiar with things like click fix and fake updates. At what point did this activity stop looking like them and start looking like its own coordinated operation?
Lauren Fevason
So the interesting thing, and so I say like click fix and fake updates. I won't say it's a group and maybe I'm speaking out of turn on this because I'm kind of starting to get into looking at this myself, admittedly more than in the past, but that's just a tactic that's being used. So what's interesting about this is we see the big piece is actually a TDS being used, a traffic distribution system. So that is the starting point. That's what's embedded into these victim websites. And from there we see it getting, you know, depending on what the victim looks like, their browser, all these other things, that's where it's getting parsed to, you know, click fix or, you know, the fake updates to even like advertisement, different advertisement distributions.
Dave Bitt
Well, let's talk about drive surge. What business are they actually in here?
Lauren Fevason
So we can't say for certain at the moment, but everything that we see and from, you know, kind of our past experiences, we believe this to be an initial access broker. So that, and that piece being more of the TDS system that's occurring. So we again believe that this group is, they're the ones going out and compromising these websites, injecting their domains into it. And in the background, that's what's happening is we initially see the TDS occurring and from there the victims are getting kind of pushed to different places. So the IAB part to us is the TDS system and then it's almost like a pay per install or pay per victim to come our way. So we imagine, again, we haven't found 100% proof one way or the other, but we imagine that someone comes and say, hey, I need victims that are using Chrome or I'm looking for people in this arena. But yeah, we just, we believe initial access brokers, you know, someone will come in and say, we need this type of person or we're looking for access in this area of the world or anything like that. You know, that traffic distribution system essentially can kind of help with that. People will click and they can see, oh, they're using this browser, they're coming from here. And so that's where. That's how we see this working.
Dave Bitt
Well, walk us through the victim journey, if you will, what happens when someone visits one of these compromised websites?
Lauren Fevason
Yeah, and I will say there's two victims really here, right? There's the compromised websites. Their sites are victimized in of itself. Yeah, but yeah, so as a person browsing to the website, and that's another interesting thing is this is all happening in the background, the TDS system that's being used. You don't see it. You'll go to the website and you can browse however, you know, and not have it. You have to really dig deep into the website code to see it. So what's happening in the background is that TDS system is collecting all sorts of information about you and you know, seeing where you're from, what kind of browser and all this stuff. And if you hit certain gates, you know, if you hit certain criteria, then this TDS system will send you to wherever it is they have it set up. So it could send you to a certain click fix where you get the pop up saying, oh, your browser is out of date, download this. It could send you certain advertisements. So those are the different things we see. And it could be certain people browse to these compromised websites and they don't see anything at all because they don't hit the criteria that's being looked for.
Dave Bitt
Now what about the compromised websites themselves? How do they fall victim here?
Lauren Fevason
Well, I would say they're victim in that, you know, they're being used in terms, you know, they're, they're, they're being compromised. Now are they losing money? I don't know. I mean, at a certain point it might be picked up that hey, this isn't a great site to go to. So this is, and I'll say this is kind of me speculating. I haven't said this is exactly what's going on or we've seen it. But you know, if you imagine if you got these small businesses, they have their website and at a certain point someone's like, hey, if you go with this website, it's bad. You know, maybe it's being blocked somewhere and you're not getting visitors. You need that, that traffic, you know, for revenue or just get your name out there. So in the media it's probably, I mean, they're victim because they're compromised. But does it hurt them in the media? Probably not, but there could be consequences down the line.
Dave Bitt
Yeah. One of the things that really struck me reading through the research was the scale of this operation. Can you share with us how extensive was this infrastructure?
Lauren Fevason
It's pretty big. So we right now tracking as of today, everything current. For example, we see 200 domains tied to this group across a number of different ip. So that's just today because we kind of look at everything going on right now and then victim wise, we're, I mean we're into the thousands probably. I don't have the exact count. I would have to kind of go back and check, but well over 5,000 I would say. And I say victim, victim websites. So it is pretty extensive.
Dave Bitt
We'll be right back when you need
Host/Announcer
to build up your team to handle the growing chaos at work. Use Indeed Sponsored Jobs. It gives your job post the boost it needs to be seen and helps reach people with the right skills, certifications and more. Spend less time searching and more time actually interviewing candidates who check all your boxes. Listeners of this show will get a $75 sponsored job credit@ Indeed.com podcast. That's Indeed.com podcast. Terms and conditions apply. Need a hiring hero? This is a job for Indeed Sponsored Jobs. This episode is brought to you by Accenture. When your advertising operations fall out of sync, everything else follows. Spotify and Accenture are working together to reinvent the rhythm of ad sales using automation, analytics and smarter workflows to simplify campaign delivery and access better data across the business. The result? Less time spent on operations, more time connecting brands with the moments and fandoms that matter most. Learn more@accenture.com Spotify
Advertiser/Commercial Voice
wishing you could be there Live for the big game. Soaking up the atmosphere of the crowd. But too often life gets busy or the price holds you back. Priceline is here to help you make it happen. With millions of deals on flights, hotels and rental cars, you can go see the game live. Don't just dream about the trip. Book it with Priceline, download the Priceline app or visit priceline.com Actual prices may vary. Limited Time Offer when it's time to
Host/Announcer
scale your business, it's time for Shopify. Get everything you need to grow the way you want. Like all the way. Stack more sales with the best converting checkout on the planet. Track your cha chings from every channel right in one spot and turn real time reporting into big time opportunities. Take your business to a whole new level. Switch to Shopify. Start your free trial today.
Dave Bitt
Your team identified some technical fingerprints here that were associated with the infrastructure. Without getting too technical, what are some of the things that you all discovered?
Lauren Fevason
Yeah, so I think there's a few different areas we've gone through and I think most probably anyone who's been an analyst will probably be shaking their head like yep, get that. Like so for example some of these domains we're seeing with registration reuse of emails. So that tends to be a good pivot point. But the other piece that we really probably a lot of our fingerprints are actually on the delivery of the tds, this particular TDS system going on. So and we kind of look at things like the URL path that's picking up the resources kind of uniquenesses in that and then we're also looking at we found some for the malware for certain pieces where it's Delivering malware. We're able to fingerprint the servers for that as well as the actual TDS server. So the server's holding. Yeah, the TDS piece that's being served through the website. So we can kind of look at the different configurations on the server side to kind of pick up where that might be.
Dave Bitt
What is your sense in terms of how long this operation has been operating? Have they been at this for a while?
Lauren Fevason
Based on the data, a lot of it starts in January of this year, so not very long. We do see for some of more of the backend servers, we see it to go back to September of 2025. That said, you know, that kind of hints at it's they're newer, wherever this group is newer. You know, I kind of caveat that with maybe they just switched infrastructures and we are just not seeing that connection farther back. So, yeah, I guess I caveat a lot. I'm sorry about that.
Host/Announcer
Yeah.
Dave Bitt
That's the nature of the beast.
Lauren Fevason
Right, Right, right. So, yeah, so we see. Like I said, we see really this particular cluster looks very new. We haven't made any connections to history yet. So as of right now, our best guess says they are new to the scene or this cluster is kind of newer. Until we discover otherwise.
Dave Bitt
Yeah. It strikes me that there's really two stories here. There's the malware delivery techniques that you've outlined, but then also there's the industrialized infrastructure behind all of this. Like we were just talking about the scale of this. Do you think that's accurate? That these are both. These are both noteworthy?
Lauren Fevason
Oh yeah, definitely. I mean, just the scale, I think. And that's where, you know, kind of going back to. We're thinking more of the IAB type group here on that scale. You know, they. That's their job, you know, going out and finding compromised web or vulnerable websites. Compromising. They're building up this infrastructure, I think in general across a lot of these online criminal activities. They almost seem like a company in of themselves. So it's not surprising to see it at scale. And then from there, you know, they likely again theorizing these are IABs, that's their company. So they're gaining access. They need a big foothold to therefore have clients of their own, you know, coming in and paying them for access.
Dave Bitt
For the security folks in our audience, for the defenders out there, what should they be considering as a result of your research here? Are there any actionable lessons that they should take away?
Lauren Fevason
I don't know if there's anything new that we all haven't heard, you know, being safe on the Internet. I think this is more towards the individuals, you know, don't go clicking on things. Even if a pop up comes up and says, hey, you need to download this, don't click yes. Don't, you know, always question everything in terms of companies? I mean it's, it's hard. It's that cat mouse game, you know, you're always trying to defend. The best to do is just try to be aware, try to go out. I know I'm not supposed to pitch our stuff, but not our stuff. But in general, you know, you've got a lot of people work, use the community of people finding these bad things. Because you can't do it alone either. I would say, you know, it's so big we have to work together. So when you indent people identify, hey, this is bad. We need to block this. You know, companies, you need to work on blocking what people have found. Oh, that's the best I could give us.
Dave Bitt
Yeah, yeah. I mean it sounds like there's definitely a, I guess a security and awareness training sort of component to this which comes with things like click fix.
Lauren Fevason
Yeah, exactly. Like I said, unfortunately, I think most of this is the end user for companies or people with their websites. You know, kind of be aware of what you know, that it can happen. But I have a feeling a lot of these website victim websites that we saw, usually they, they're not setting up their own servers, they have someone else doing it for them or they're using a service online, you know, to set up these websites. So it's just, it's hard to say, go out and look at your website and make sure, you know, it's not compromised. It's hard to do that, I'm sure on their own. But that is one way, you know, at least have that in mind. Or I think companies need to be aware that it's possible and probably hopefully go out and find resources for that. And then, yeah, the other side, you know, the people behind the computer clicking the mouse, you just, yep, that awareness. Can't trust, pretty much can't trust almost anything. You know, second guess, second, don't just jump right in, you know, always wonder why something's there or if something, you know, immediately pops up, say, well, why now? You know, close out and go look somewhere else and make sure that's what you really need.
Dave Bitt
Our thanks to Lauren Fiveson from Silent Push for joining us. The research is titled Meet Drive Surge, A new threat actor using click fix and fake update drive by attacks in thousands of compromised sites. We'll have a link in the Show Notes. That's Research Saturday brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the Show Notes or send an email to cyberwire2k.com this episode was produced by Liz Stokes. We're mixed by Elliot Teltzman and Trey Hester, our executive producers Jennifer Ibin, Peter Kilpe is our publisher and I'm Dave Bittner. Thanks for listening. We'll see you back here next time.
Advertiser/Commercial Voice
The Right Window treatments change everything. Your sleep, your privacy, the way every room looks and feels. @blinds.com, we've spent 30 years making it surprisingly simple to get exactly what your home needs. We've covered over 25 million windows and have 50,000 five star reviews to prove we deliver. Whether you DIY it or want a pro to handle everything from measure to install, we have you covered. Real Design professionals free samples, zero pressure right now. Get up to 40% off site wide plus get a free professional measure@blinds.com rules and restrictions apply.
Host/Announcer
Close your eyes, exhale, feel your body relax and let go of whatever you're carrying today. Well, I'm letting go of the worry that I wouldn't get my new contacts in time for this class. I got them delivered free from 1-800-contacts. Oh my gosh, they're so fast.
Lauren Fevason
And breathe. Oh sorry.
Host/Announcer
I almost couldn't breathe when I saw the discount they gave me on my first order. Oh, sorry.
Lauren Fevason
Namaste.
Host/Announcer
Visit 1-800-contacts.com today to save on your first order.
Lauren Fevason
1-800-contacts.
Host/Announcer
Starting a business can seem like a daunting task unless you have a partner like Shopify. They have the tools you need to start and grow your business. From designing a website to marketing to selling and beyond, Shopify can help with everything you need. There's a reason millions of companies like Mattel, Heinz and Allbirds continue to trust and use them. With Shopify on your side, turn your big business idea into Sign up for your $1 per month trial@shopify.com specialoffer.
Research Saturday – July 18, 2026
Host: Dave Bittner (N2K Networks)
Guest: Lauren Fevason (Senior Threat Researcher, Silent Push)
Topic: Meet Drive Surge, a new threat actor using click-fix and fake-update drive-by attacks via thousands of compromised sites
This episode uncovers “Drive Surge,” a concerning new threat actor leveraging compromised trusted websites to execute large-scale drive-by and malvertising campaigns. The conversation with Lauren Fevason from Silent Push explains the tactics behind click-fix and fake-update attacks, the industrialized infrastructure supporting them, and the impact both on website owners and unsuspecting visitors. The discussion provides unique insights for defenders and the broader cybersecurity audience on the mechanics of this threat and practical takeaways.
[01:49 – 02:35]
Bulletproof Hosting Connection: Researchers started tracking Drive Surge by examining domains hosted by “Nicenic,” an identified bulletproof hosting provider, to analyze behaviors commonly associated with malicious infrastructure.
Resource Clustering: By mapping the domains and resources provided to hacked websites, a significant cluster—labeled “Drive Surge”—was uncovered.
“We found this big cluster that we have said is Drive Surge.”
— Lauren Fevason [02:35]
[03:16 – 05:51]
Not Just Tactics, But an Operation: While “click-fix” and “fake update” are established techniques, the true innovation is the use of a Traffic Distribution System (TDS) as central infrastructure.
Likely Initial Access Broker (IAB): Drive Surge likely acts as an IAB, compromising websites and using the TDS for targeted delivery based on victim characteristics (browser, location, etc.), before selling or renting access to downstream criminal customers.
“We believe this to be an initial access broker…The TDS system essentially can kind of help with that. People will click and they can see, oh, they're using this browser, they're coming from here. And so that’s where…that’s how we see this working.”
— Lauren Fevason [04:17–05:51]
[05:51 – 07:13]
Compromised Sites as Unknowing Accomplices: Legitimate websites are hijacked through injected code. The compromise is often invisible to owners and visitors unless deeper inspection is done.
End-users at Risk: Visitors may be redirected by the TDS to malware, fake updates, or scams if they match attacker’s target criteria. Many see no symptoms at all.
“There’s two victims…there’s the compromised websites. Their sites are victimized in of itself…as a person browsing to the website…you don’t see it. You have to really dig deep into the website code to see it.”
— Lauren Fevason [05:59–07:13]
[07:13 – 08:10]
Most victimized sites are small businesses, possibly losing visitors (and thus revenue) as word spreads or as browsers flag their sites.
Direct financial loss is uncertain but reputational harm and traffic reduction are likely over time.
“If you imagine…at a certain point someone’s like, hey, if you go with this website it’s bad…you need that traffic…for revenue or just to get your name out there.”
— Lauren Fevason [07:18]
[08:10 – 08:58]
Extensive Operation: Over 200 domains linked to Drive Surge across multiple IPs, with >5,000 victim websites detected as of recording.
“It's pretty big…as of today…we see 200 domains tied to this group…victim-wise, we’re, I mean, we’re into the thousands…well over 5,000 I would say…victim websites.”
— Lauren Fevason [08:20]
[11:03 – 12:20]
Registration Reuse: Analysts track reused registration emails and domain infrastructure.
TDS Delivery & Server Analysis: Unique URL patterns, malware delivery methods, and server configurations help researchers link domains and websites to Drive Surge’s infrastructure.
“Some of these domains…with registration reuse of emails…most of our fingerprints are actually on the delivery of the TDS…we're able to fingerprint the servers for that as well as the actual TDS server.”
— Lauren Fevason [11:15]
[12:20 – 13:01]
Timeline: The cluster’s main activity dates from January 2026, though a few backend servers suggest operations as early as September 2025. The group or at least this campaign is considered “very new.”
“Based on the data, a lot of it starts in January of this year…maybe they just switched infrastructures and we are just not seeing that connection farther back.”
— Lauren Fevason [12:26]
[13:22 – 14:26]
Corporate-Style Operations: Drive Surge builds and scales professionalized infrastructure, mirroring legitimate organizations in their operational rigor.
Service Model: Like many IABs, their “clients” are likely other criminals seeking specific targets or types of victims.
“They almost seem like a company in of themselves. So it’s not surprising to see it at scale.”
— Lauren Fevason [13:43]
[14:26 – 17:12]
User Vigilance: Main defense for individuals is skepticism toward unsolicited browser warnings and pop-ups (“don’t click yes,” “always question everything”).
Companies & Website Admins: Encouraged to collaborate and share threat intelligence; monitoring and blocking malicious indicators as they’re discovered is essential.
Challenges for Small Businesses: Many victim websites are provided by third parties; direct monitoring can be tough for non-technical owners, underscoring need for widespread community vigilance.
“The best to do is just try to be aware…you can't do it alone either…I would say…it’s so big we have to work together.”
— Lauren Fevason [14:39]
“Can’t trust, pretty much can’t trust almost anything. You know, second guess…if something…immediately pops up, say, well, why now? You know, close out and go look somewhere else and make sure that's what you really need.”
— Lauren Fevason [15:49, 16:40]