Skip to content
← All Threat Actors
Cybercrime critical Unknown

DriveSurge

Financially motivated initial access broker (origin unknown) · Financial — initial access brokering to ransomware operators

Reports 1
Active Since 2025
Last Reported 21 Jul 2026
Sectors Targeted finance, critical-infrastructure

Tactics, Techniques & Procedures (TTPs)

  • Rapid exploitation of critical CVEs in enterprise software within weeks of disclosure (CVE-2026-46817: Oracle EBS Payments RCE exploited ~6 weeks post-patch)
  • Unauthenticated RCE exploitation for initial access — targets software with large enterprise installed bases across finance, government, and healthcare sectors
  • Persistence establishment and light internal reconnaissance to assess target financial profile and cyber insurance status
  • Access brokering to ransomware affiliates — typical dwell time between DriveSurge access and ransomware deployment: two to five weeks
  • Exfiltration of high-value data (payroll, payment configurations) as part of access validation and leverage establishment
  • Targeting of on-premises enterprise software with internet-facing exposure (Oracle EBS, enterprise ERP)

Known Targets

Oracle E-Business Suite deployments (finance sector, government procurement)Enterprise ERP environments across manufacturing and logisticsFinance departments running on-premises ERP with internet-facing payment componentsNissan payroll processing environment (June 2026 — employee payroll data exfiltrated)

Analyst Notes

DriveSurge is a financially motivated initial access broker documented in threat intelligence reporting around the exploitation of CVE-2026-46817 (Oracle EBS Payments RCE, CVSS 9.8, CISA KEV July 2026). The group's model follows the IAB playbook: rapid weaponisation of newly disclosed critical CVEs, establishment of persistence, profiling of the target, and sale of access to ransomware affiliates who conduct the final extortion. The Oracle EBS focus is notable — EBS deployments run payroll, procurement, and treasury operations for major enterprises and government bodies, giving initial access high leverage value well beyond a conventional web server compromise. Dwell times of two to five weeks between DriveSurge access and ransomware deployment indicate deliberate staging, not opportunistic smash-and-grab.