New SocGholish Infection Chain Discovered
ID: ea4f9227-b02f-5b74-a8e7-e33086e6f38e
STIX ID: report--ea4f9227-b02f-5b74-a8e7-e33086e6f38e
Feed Name: ReliaQuest Blog
This report describes a Q1 2024 observation of SocGholish (FakeUpdates) JavaScript payloads that download an embedded Python 3.12 runtime from python.org, rename and execute a malicious Python script (hklib.py), and create a scheduled task (“pypi-py”) to persistently run the script (likely a SOCKS5 C2 client) against IP 92.118.112.208:443; it includes the full observed command chain, IOCs (oystergardens.club, hash, IP), and mitigation recommendations such as restricting script execution, application control, and EDR blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
