logo

RansomHub Leverages SocGholish FakeUpdates to Target Government Sector

ID: 5d057716-f8c7-5c9c-a770-bd3c2945e797

STIX ID: report--5d057716-f8c7-5c9c-a770-bd3c2945e797

Feed Name: Halcyon Blog

Threat Score
80/100

Date Published: 2025-04-15

Date Updated: 2026-04-28

...
...

Researchers report a large-scale RansomHub ransomware campaign using the SocGholish/FakeUpdates malvertising chain: thousands of compromised (primarily WordPress) sites redirect real users via Keitaro TDS to fake update pages that drop obfuscated JavaScript loaders and Python-based backdoors, enable domain-shadowed C2, data exfiltration and double-extortion; RansomHub operates as a RaaS with high affiliate payouts, exploits known CVEs and brute-force access, and has claimed hundreds of victims across multiple sectors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.