logo

New SocGholish Infection Chain Discovered

ID: ea4f9227-b02f-5b74-a8e7-e33086e6f38e

STIX ID: report--ea4f9227-b02f-5b74-a8e7-e33086e6f38e

Feed Name: ReliaQuest Blog

Threat Score
65/100

Date Published: 2024-02-13

Date Updated: 2026-04-29

...
...

This report describes a Q1 2024 observation of SocGholish (FakeUpdates) JavaScript payloads that download an embedded Python 3.12 runtime from python.org, rename and execute a malicious Python script (hklib.py), and create a scheduled task (“pypi-py”) to persistently run the script (likely a SOCKS5 C2 client) against IP 92.118.112.208:443; it includes the full observed command chain, IOCs (oystergardens.club, hash, IP), and mitigation recommendations such as restricting script execution, application control, and EDR blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.