Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
ID: 741431b6-a7da-5999-b1c5-93a3e7d42b83
STIX ID: report--741431b6-a7da-5999-b1c5-93a3e7d42b83
Feed Name: ThreatCluster
Threat Score
On June 18, 2026, international law enforcement (Netherlands, Canada, US, Germany, supported by Europol) executed Operation Endgame, disrupting the SocGholish/FakeUpdates malware infrastructure linked to Evil Corp by remediating 14,971 infected WordPress sites and taking down 106 servers/domains; SocGholish abused compromised legitimate websites to deliver fake software updates to compromise users, and authorities advised site owners to harden credentials and enable MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
