DriveSurge
Financially motivated initial access broker (origin unknown) · Financial — initial access brokering to ransomware operators
Tactics, Techniques & Procedures (TTPs)
- Rapid exploitation of critical CVEs in enterprise software within weeks of disclosure (CVE-2026-46817: Oracle EBS Payments RCE exploited ~6 weeks post-patch)
- Unauthenticated RCE exploitation for initial access — targets software with large enterprise installed bases across finance, government, and healthcare sectors
- Persistence establishment and light internal reconnaissance to assess target financial profile and cyber insurance status
- Access brokering to ransomware affiliates — typical dwell time between DriveSurge access and ransomware deployment: two to five weeks
- Exfiltration of high-value data (payroll, payment configurations) as part of access validation and leverage establishment
- Targeting of on-premises enterprise software with internet-facing exposure (Oracle EBS, enterprise ERP)
Known Targets
Analyst Notes
DriveSurge is a financially motivated initial access broker documented in threat intelligence reporting around the exploitation of CVE-2026-46817 (Oracle EBS Payments RCE, CVSS 9.8, CISA KEV July 2026). The group's model follows the IAB playbook: rapid weaponisation of newly disclosed critical CVEs, establishment of persistence, profiling of the target, and sale of access to ransomware affiliates who conduct the final extortion. The Oracle EBS focus is notable — EBS deployments run payroll, procurement, and treasury operations for major enterprises and government bodies, giving initial access high leverage value well beyond a conventional web server compromise. Dwell times of two to five weeks between DriveSurge access and ransomware deployment indicate deliberate staging, not opportunistic smash-and-grab.