SocGholish Malware Delivered via Compromised Web Pages and Weaponized ZIP Files
ID: a78868b1-1efb-57a8-bfd7-1584035f55b4
STIX ID: report--a78868b1-1efb-57a8-bfd7-1584035f55b4
Feed Name: Cyber Press
SocGholish ("FakeUpdates") is a persistent drive-by download malware campaign that compromises legitimate websites to prompt users into downloading weaponized ZIP files containing obfuscated JavaScript; once executed the malware stages further payloads, communicates with C2 servers using encoded/encrypted channels, and establishes persistence (e.g., scheduled tasks or PowerShell). The campaign is attributed to Evil Corp, has demonstrated large scale (reported 1.5 million user interactions in a week), and is used to deliver secondary payloads including ransomware and remote access tooling; recommended defenses include EDR, web filtering, user training, and ensuring official software updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
