logo

Authorities Dismantle SocGholish Malware Network — 106 Servers and 101 Domains Seized

ID: 5bf008ed-e161-52c0-b273-31f3f7774e60

STIX ID: report--5bf008ed-e161-52c0-b273-31f3f7774e60

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-06-18

Date Updated: 2026-06-19

Author: Guru Baran

...
...

Operation Endgame—an international law-enforcement effort involving the NHTCU, RCMP, FBI, BKA, Europol and Eurojust—disrupted the long-running SocGholish (FakeUpdates) malware framework by seizing 106 servers, 101 domains and remediating roughly 14,971 infected WordPress sites; SocGholish uses injected malicious JavaScript to present fake browser update prompts that install backdoors and payloads (RATs, infostealers, Cobalt Strike, ransomware) and has been linked to the Evil Corp criminal group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.