SocGholish: A Tale of FakeUpdates
ID: f3a6ff7e-61b9-5415-bb06-bde51f0d31fd
STIX ID: report--f3a6ff7e-61b9-5415-bb06-bde51f0d31fd
Feed Name: ReliaQuest Blog
ReliaQuest investigated two SocGholish (FakeUpdates) intrusions in which malicious JavaScript installers delivered stage payloads that established C2, dropped Cobalt Strike beacons, and progressed toward ransomware objectives; investigators identified stage domains (e.g., taxes.rpacx.com, *.signing.unitynotarypublic.com, *.asset.tradingvein.xyz), C2 IP 88.119.169.108, and a Cobalt Strike server change-land.com (31.184.254.115) with ties to Evil Corp, documented endpoint techniques (WMIC, disabling RestrictedAdmin, PowerSharpPack download), and provided containment and mitigation recommendations (GPO to open JS in Notepad, centralized logging, user training).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
