BigTech CompaniesCybersecurityNewswireTechnology

Law Enforcement Takedown Hits SocGholish: 106 Servers Down, 15,000 Sites Cleaned

Originally published on: June 19, 2026
▼ Summary

– International law enforcement coalition Operation Endgame took down 106 servers and domains linked to SocGholish, and cleaned nearly 15,000 compromised websites.
– SocGholish infects victims by compromising WordPress sites with obfuscated JavaScript that profiles browsers and displays fake update prompts to deliver malware.
– The operation is run by TA569, associated with Russian cybercriminal group Evil Corp, and has posed a major threat to enterprises since 2017.
– Law enforcement notified and helped clean compromised WordPress sites; owners are advised to update CMS, use strong passwords, and enable multi-factor authentication.
– Canadian police developed a disruption technique that disinfected 2,488 computers and prevents future re-infection; over 154,000 compromised email addresses were added to Have I Been Pwned.

An international crackdown has dealt a severe blow to the SocGholish malware operation, a long-running threat that tricked users into downloading malicious software through fake browser update prompts. As part of Operation Endgame, law enforcement agencies seized 106 servers and domains tied to the operation and cleaned nearly 15,000 compromised websites that were used to deliver its payloads. The Dutch National Police announced the takedown this week, detailing the scope of the action on the operation’s official website.

The SocGholish infection chain typically begins when attackers compromise legitimate WordPress sites, injecting them with heavily obfuscated JavaScript. According to researchers at Proofpoint, this script profiles each visitor’s browser to ensure they are not developers or site administrators. It checks that DevTools are closed, confirms the visitor hasn’t encountered the lure before, and waits for natural mouse movement before proceeding. Only after passing these checks does the script replace the entire page with a fake browser update prompt. If the victim downloads and runs the file, a disguised JavaScript payload silently connects to attacker-controlled infrastructure, deploying a second-stage payload , usually an infostealer or remote access tool.

The group behind SocGholish, known as TA569, has been active since 2017 and is linked to the Russian cybercriminal group Evil Corp. “This group has previously been responsible for Zeus and Dridex malware and is also associated with several large‑scale ransomware and money‑laundering operations,” the Dutch Police stated. Infoblox’s threat intelligence team added that “for the last nine years, SocGholish, operated by TA569, has posed a major threat to enterprise organizations around the world.” Their analysis found that nearly 55% of customer networks in their dataset attempted to reach SocGholish infrastructure over a five-month period. While most attempts did not lead to active compromise, a small number of networks were potentially impacted by on-device execution of the payload.

Infoblox believes this law enforcement action will reduce SocGholish activity, but the long-term impact remains uncertain. “The key question now is if and how quickly the actors can adapt: whether they attempt to rebuild the existing ecosystem, shift to alternative infrastructure, or move on to new delivery models,” they noted. The group has historically controlled as many as a million sites at various points, often compromising websites directly or accepting traffic from affiliates.

As part of the takedown, law enforcement notified owners of compromised WordPress sites and helped clean and secure them. WordPress site owners are urged to keep their CMS and plugins updated, use strong passwords, enable multi-factor authentication on admin accounts, and delete any unknown additional accounts they may find.

In a related development, the Royal Canadian Mounted Police announced that investigators with the Cybercrime Investigation Team – Vancouver developed a disruption technique to interrupt SocGholish malware. Working with international partners, they refined the method to achieve a mass disinfection of 2,488 computers worldwide. The technique is also designed to prevent future re-infection of cleaned sites with SocGholish.

Additionally, a searchable list of 154,000 email addresses and over half a million passwords compromised by SocGholish has been added to the Have I Been Pwned service, allowing users to check if their credentials were exposed.

(Source: Help Net Security)

Topics

socgholish malware 98% law enforcement action 95% fake software updates 92% wordpress compromise 90% ta569 threat actor 88% infostealer payloads 85% operation endgame 83% browser profiling 80% enterprise threat 78% website security 75%