Incident report: Spotting SocGholish WordPress injection
ID: 4c401d56-9f27-5af3-aae5-b0c451521aa4
STIX ID: report--4c401d56-9f27-5af3-aae5-b0c451521aa4
Feed Name: Expel Blog
Date Published: 2021-07-22
Date Updated: 2026-04-27
Author: Tyler Fornes; Ryan Gott; Kyle Pellett; Evan Reichard
A SOC detected and stopped a SocGholish drive-by campaign where a compromised WordPress site served an obfuscated inline script that delivered a zipped JScript ("Chrome.Update.js") RAT to Windows visitors; EDR blocked execution on multiple hosts, investigators traced downloads to the site, identified C2 domains and likely exploitation of WordPress 5.5.3 or a plugin, and assisted the customer with removing malicious scripts, patching, and containment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
