logo

15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown

ID: 2e08ae50-1044-5e46-a065-7455de0f65bf

STIX ID: report--2e08ae50-1044-5e46-a065-7455de0f65bf

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

...
...

Operation Endgame disrupted the SocGholish (aka FakeUpdates) distribution network by seizing 106 command-and-control servers and domains and enabling cleanup of approximately 15,000 compromised WordPress sites; the report details SocGholish's JavaScript-based fake-update injection vector, its use to deliver RATs, Cobalt Strike beacons and ransomware loaders, association with Evil Corp, and recommended remediation steps for site owners.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.