logo

Operation Endgame Disrupts Evil Corp's SocGholish Malware Network

ID: 7aac8971-5d60-5b89-b243-1551dc79ebf1

STIX ID: report--7aac8971-5d60-5b89-b243-1551dc79ebf1

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-22

...
...

On June 18, 2026, international law enforcement launched Operation Endgame, disrupting the SocGholish/FakeUpdates malware infrastructure tied to the Russian cybercrime group Evil Corp; the action remediated 14,971 infected WordPress sites and removed 106 servers and domains, and authorities advised improved site security such as credential changes and multi-factor authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.