logo

Police Cleans Nearly 15,000 SocGholish-Infected Sites Tied to Evil Corp

ID: c170ad43-871d-5312-9ea5-36f0d24a7393

STIX ID: report--c170ad43-871d-5312-9ea5-36f0d24a7393

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

...
...

A coordinated international law enforcement operation disrupted the SocGholish (FakeUpdates) JavaScript malware distribution network operated by Evil Corp, disinfecting roughly 15,000 compromised WordPress sites, seizing over 100 servers, and sinkholing command-and-control domains; SocGholish acted as a distributed dropper and initial access broker historically delivering NetSupport RAT and facilitating ransomware, credential theft, and long-term access. Site owners are advised to audit JavaScript and PHP files, check plugins, enable file integrity monitoring or a WAF, and update WordPress components.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.