Law enforcement hits SocGholish: 106 servers down, 15,000 sites cleaned
ID: 0aa0de5d-5abb-538a-a2b2-4108e3b6a3a2
STIX ID: report--0aa0de5d-5abb-538a-a2b2-4108e3b6a3a2
Feed Name: Help Net Security
SocGholish — operated by TA569 and tied to Evil Corp — has long distributed malware via obfuscated JavaScript injected into compromised WordPress sites that presents fake browser-update prompts to deliver infostealers or remote access tools; a recent multinational Operation Endgame takedown removed 106 servers/domains and helped clean nearly 15,000 compromised sites, while researchers warn actors may rebuild or change delivery models and advise WordPress owners to update, use strong authentication, and remove unknown accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
