logo

Threat Actors Leverage Fake Update Lures to Deliver SocGholish Malware

ID: 16b4650c-de3a-5762-82f8-a8aacfbabbae

STIX ID: report--16b4650c-de3a-5762-82f8-a8aacfbabbae

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2025-11-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

SocGholish is a widespread malware delivery framework that compromises legitimate websites to present convincing fake software-update prompts, leading users to download obfuscated JavaScript loaders and secondary payloads; operators use PowerShell evasion techniques, scheduled tasks and Python backdoors for persistence, and the framework has recently been observed delivering Mythic Agent and acting as a gateway for ransomware against organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.