logo

Law enforcement hits SocGholish: 106 servers down, 15,000 sites cleaned

ID: 0aa0de5d-5abb-538a-a2b2-4108e3b6a3a2

STIX ID: report--0aa0de5d-5abb-538a-a2b2-4108e3b6a3a2

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Zeljka Zorz

...
...

SocGholish — operated by TA569 and tied to Evil Corp — has long distributed malware via obfuscated JavaScript injected into compromised WordPress sites that presents fake browser-update prompts to deliver infostealers or remote access tools; a recent multinational Operation Endgame takedown removed 106 servers/domains and helped clean nearly 15,000 compromised sites, while researchers warn actors may rebuild or change delivery models and advise WordPress owners to update, use strong authentication, and remove unknown accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.