
When trusted sites turn.
Dave Bittner: Hello, everyone and welcome to the CyberWire's "Research Saturday." I'm Dave Bittner and this is our weekly conversation with researchers and analysts tracking down the threats and vulnerabilities, solving some of the hard problems and protecting ourselves in our rapidly evolving cyberspace. Thanks for joining us. [ Music ]
Lauren Fievisohn: This one in particular, it pulled from two different places. So, one is bulletproof hosting providers. Particularly one of our recent or past white papers. We've identified NiceNIC as a bulletproof hosting provider. So, we have that on the one end and then on the other side just kind of this idea of, "Okay, what are general behaviors of bad?" You know? So, that's the other side. So, we were thinking, "Okay, let's look at everything that's hosted on NiceNIC." And then looking to see of those domains, which ones are providing resources to websites. And through that, you know, kind of looking at those behaviors, we found this big cluster that we have, said is Drive Surge.
Dave Bittner: That's Lauren Fievisohn, senior threat researcher from Silent Push. The research we're discussing today is titled "Meet Drive Surge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites." [ Music ] So, I -- I think probably most of our listeners are familiar with things click fix and fake updates. At what point did this activity stop looking like them and start looking like its own coordinated operation?
Lauren Fievisohn: So, the interesting thing, and so I'd say like click fix and fake updates, I won't say it's a group and maybe I'm speaking out of turn on this because I'm kind of starting to get into looking at this myself, admittedly more than in the past. But that's just a tactic that's being used. So, what's interesting about this is we see the big piece is actually a TDS being used, a traffic distribution system. So, that is the starting point. That's what's embedded into these victim websites. And from there, we see it getting, you know, depending on what the victim looks like, their browser, all these other things, that's where it's getting parsed to, you know, click fix or, you know, the fake updates to even like advertisement, different advertisement distributions.
Dave Bittner: Well, let's talk about DriveSurge. What business are they actually in here?
Lauren Fievisohn: So, we can't say for certain at the moment, but everything that we see and from, you know, kind of our past experiences, we believe this to be an initial access broker. So that -- and that piece being more of the TDS system that's occurring. So, we again believe that this group is -- they're the ones going out and compromising these websites, injecting their domains into it. And in the background, that's what's happening is we initially see the TDS occurring. And from there, the victims are getting kind of pushed to different places. So, the IAB part to us is the TDS system. And then it's almost like a pay-per-install or pay-per you know, victim to come our way. So, we imagine, again, we haven't found 100% proof one way or the other, but we imagine that, you know, someone comes and say, "Hey, I need victims that are using Chrome," or "I'm looking for people in this arena." But yes, we just -- we believe initial ask brokers, you know, someone will come in and say, "We need this type of person," or "We're looking for access in this area of the world," or anything like that. You know, traffic distribution system essentially can kind of help with that. People will click and they can see, "Oh, they're using this browser. they're coming from here." And so, that's where -- that's how we see this working.
Dave Bittner: Well, walk us through the victim journey, if you will. What happens when someone visits one of these compromised websites?
Lauren Fievisohn: Yes, and I'll say there's two victims really here. Right? There's the compromised websites. Their sites are victimized in and of itself.
Dave Bittner: Yes.
Lauren Fievisohn: But, yes. So, as a person browsing to the website, and that's another interesting thing is this is all happening in the background. The TDS system that's being used, you don't see it. You'll go to the website, and you can browse however, you know, and not have it. You have to really dig deep into the website code to see it. So,what's happening in the background is that TDS system is collecting all sorts of information about and you know, seeing where you're from, what kind of browser and all this stuff. And if you hit certain gates, you know, if you hit certain criteria, then this TDS system will send you to wherever it is they have it set up. So, it could send you to a certain click fix where, you know, you get the pop up saying, "Oh, your browser is out of date. Download this." It could send you certain advertisements. So, those are the different things we see. And it could be certain people browse to these compromised websites and they don't see anything at all because they don't hit the criteria that's being looked for.
Dave Bittner: Now, what about the compromised websites themselves? How do they fall victim here?
Lauren Fievisohn: Well, I would say they're victim in that, you know, they're being used in terms --
Dave Bittner: Yes.
Lauren Fievisohn: -- you know, they're -- they're -- they're being compromised. Now, are they losing money? I don't know. I mean at a certain point it might be picked up that, "Hey, this isn't a great site to go to." So, this is -- and I'll say, this is kind of me speculating. I haven't said this is exactly what's going on or we've seen it. But, you know, if you imagine if you got these small businesses, they have their website and at a certain point someone's like, "Hey, if you go with this website, it's bad." You know, maybe it's being blocked somewhere and you're not getting visitors. You need that -- that traffic, you know, for revenue or just get your name out there. So, in the media it's probably -- I mean, they're a victim because they're compromised. But does it hurt them in the media? Probably not, but there could be consequences down the line.
Dave Bittner: Yes. One of the things that really struck me reading through the research was the scale of this operation. Can you share with us how extensive was this infrastructure?
Lauren Fievisohn: It's pretty big. And so, we right now tracking as of today, everything current, for example, we see 200 domains tied to this group, across a number of different IPs. So, that's just today because we kind of look at everything going on right now. And then victim wise, where I mean we're into the thousands probably. I don't have the exact count. I would have to kind of go back and check, but well over 5,000 I would say victim -- and when I say victim, victim websites. So, it is pretty extensive.
Dave Bittner: We'll be right back. [ Music ] Your team identified some technical fingerprints here that were associated with the infrastructure. Without getting too technical, what are some of the things that you all discovered?
Lauren Fievisohn: Yes, so I think there's a few different areas we've gone through and I think most probably anyone who's been an analyst will probably be shaking their head like, "Yes, I get that." Like, so for example, some of these domains, we're seeing with registration, reuse of emails. So, that tends to be a good pivot point. But the other piece that we really probably a lot of our fingerprints are actually on the delivery of the TDS, this particular TDS system going on. So, and -- and we kind of look at things like the URL path that's picking up the resources, kind of uniquenesses in that. And then we're also looking at -- we found some for the malware, for certain pieces where it's delivering malware, we're able to fingerprint the servers for that as well as the actual TDS server. So, the servers holding, yes, the TDS piece that's being served through the website. So, we can kind of look at the different configurations on the server side to kind of pick up where that might be.
Dave Bittner: What is your sense in terms of how long this operation has been operating? Have -- have they been at this for a while?
Lauren Fievisohn: Based on the data, a lot of it starts in January of this year, so not very long. We do see for some of more the back-end servers, we see it to go back to September of 2025. That said, you know, that kind of hints at it's -- they're newer, wherever this group is newer. You know, I kind of caveat that with maybe they just switched infrastructures and we're just not seeing that connection farther back. So yes, I guess I caveat a lot. I'm sorry about that.
Dave Bittner: Yes, that's the nature of the beast. Right?
Lauren Fievisohn: Right, right. So, yes, so we see -- like I said, we see really this particular cluster looks very new. We haven't made any connections to history yet. So, as of right now, you know, our best guess says they are new to the scene or this cluster is kind of newer until we, you know, discover otherwise.
Dave Bittner: Yes. It strikes me that there's -- there's really two stories here. There's -- there's the malware delivery techniques that you've outlined, but then also there's the industrialized infrastructure behind all of this. Like we were just talking about, the scale of this. Do you -- do you think that's -- that's accurate, that these are both worth -- these are both noteworthy?
Lauren Fievisohn: Oh yes, definitely. I mean just the scale, I think -- and that's where, you know, kind of going back to, we're thinking more of the IAB type group here on that scale. You know, they -- that's their job, you know, going out and finding compromised web or vulnerable websites. Compromising. They're building up this infrastructure. I think in general, across a lot of these online criminal activities, they almost seem like a company in and of themselves. So, it's not surprising to see it at scale. And then from there, you know, they likely again theorizing these are IABs, that's their company. So, they're gaining access. They need a big foothold to therefore have clients of their own, you know, coming in and paying them for access.
Dave Bittner: For the security folks in our audience, for the defenders out there, what should they be considering as a result of your research here? Are there any actionable lessons that they should take away?
Lauren Fievisohn: I don't know if there's anything new that we all haven't heard, you know --
Dave Bittner: Yes.
Lauren Fievisohn: -- you know, being safe on the Internet. I think this is more towards the individuals, you know, don't go clicking on things. Even if a pop up comes up and says, "Hey, you need to download this," don't click "Yes." Don't, you know, always question everything. In terms of companies, I mean, it's -- it's hard. It's that cat and mouse game, you know, you're always trying to defend. The best to do is just try to be aware, try to go out. I know I'm not supposed to pitch our stuff, but not our stuff in general. You know, you've got a lot of people work -- use the community of people finding these bad things because you can't do it alone either, I would say. You know, it's so big. We have to work together. So, when you -- people identify, "Hey, this is bad. We need to block this." You know, companies, you need to work on blocking what people have found. So, that's the best I could give us.
Dave Bittner: Yes, yes. I mean it sounds like there's definitely a, I guess, a security and awareness training sort of component to this which comes with things like click fix.
Lauren Fievisohn: Yes, exactly. Like I said, unfortunately, I think most of this is the end user for companies or people with their websites. You know, kind of be aware of what, you know, that it can happen. But I have a feeling a lot of these website -- victim websites that we saw, usually they -- they're not setting up their own servers. They have someone else doing it for them or they're using a service online, you know, to set up these websites. So, it's just -- it's hard to say, "Go out and look at your website and make sure, you know, it's not compromised." It's hard to do that, I'm sure on their own, but that is one way. You know, you at least have that in mind. Or I think companies need to be aware that it's possible and probably, hopefully go out and find resources for that. And then, yes, the other side, you know, the people behind the computer, clicking the mouse, you just -- yes, that awareness. You can't trust -- pretty much can't trust almost anything.
Dave Bittner: Right.
Lauren Fievisohn: You know, second guess -- second -- don't just jump right in. You know, always wonder why something's there or if something, you know, immediately pops up, say, "Well, why now?" You know? Close out and go look somewhere else and make sure that's what you really need. [ Music ]
Dave Bittner: Our thanks to Lauren Fievisohn from Silent Push for joining us. The research is titled "Meet Drive Surge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites." We'll have a link in the Show Notes. That's "Research Saturday," brought to you by N2K CyberWire. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like our show, please share a rating and review in your favorite podcast app. Please also fill out the survey in the Show Notes or send an email to cyberwire@n2k.com. This episode was produced by Liz Stokes. We're mixed by Elliott Peltzman and Tre Hester. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher, and I'm Dave Bittner. Thanks for listening. We'll see you back here next time. [ Music ]
