Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
ID: 17406d79-47c9-5fef-a54e-b849f0483230
STIX ID: report--17406d79-47c9-5fef-a54e-b849f0483230
Feed Name: CosmicBytez Labs
Threat Score
**Operation Endgame** reports that Dutch authorities, with partners from Canada, Germany, and the U.S., disrupted the SocGholish (FakeUpdates) JavaScript malware/inital-access broker by seizing command-and-control infrastructure and cleaning 14,971 infected WordPress sites—cutting off a supply line used by ransomware groups (including Evil Corp-linked variants) and other criminal actors, while providing technical remediation and hardening guidance for site owners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
