Police Cleans Nearly 15,000 SocGholish-Infected Sites Tied to Evil Corp
ID: c170ad43-871d-5312-9ea5-36f0d24a7393
STIX ID: report--c170ad43-871d-5312-9ea5-36f0d24a7393
Feed Name: CosmicBytez Labs
A coordinated international law enforcement operation disrupted the SocGholish (FakeUpdates) JavaScript malware distribution network operated by Evil Corp, disinfecting roughly 15,000 compromised WordPress sites, seizing over 100 servers, and sinkholing command-and-control domains; SocGholish acted as a distributed dropper and initial access broker historically delivering NetSupport RAT and facilitating ransomware, credential theft, and long-term access. Site owners are advised to audit JavaScript and PHP files, check plugins, enable file integrity monitoring or a WAF, and update WordPress components.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
