logo

SocGholish Malware Delivered via Compromised Web Pages and Weaponized ZIP Files

ID: a78868b1-1efb-57a8-bfd7-1584035f55b4

STIX ID: report--a78868b1-1efb-57a8-bfd7-1584035f55b4

Feed Name: Cyber Press

Threat Score
76/100

Date Published: 2025-02-14

Date Updated: 2026-04-13

Author: Mandvi

...
...

SocGholish ("FakeUpdates") is a persistent drive-by download malware campaign that compromises legitimate websites to prompt users into downloading weaponized ZIP files containing obfuscated JavaScript; once executed the malware stages further payloads, communicates with C2 servers using encoded/encrypted channels, and establishes persistence (e.g., scheduled tasks or PowerShell). The campaign is attributed to Evil Corp, has demonstrated large scale (reported 1.5 million user interactions in a week), and is used to deliver secondary payloads including ransomware and remote access tooling; recommended defenses include EDR, web filtering, user training, and ensuring official software updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.