Threats

SocGholish Malware Botnet Disrupted by Authorities

June 23, 2026 00:16 · 10 min read
SocGholish Malware Botnet Disrupted by Authorities

Global Effort to Disrupt SocGholish Botnet

On Thursday, authorities from around the world collaborated to disrupt a botnet and seize infrastructure used by Evil Corp and other cybercrime groups to steal data and break into various networks. The targeted botnet, known as SocGholish, is a multi-stage malware that has compromised websites, redirected users to traffic distribution systems (TDS), and slipped malware into their networks since 2017.

The FBI's cyber division explained that the malware establishes an initial foothold into victim computers, collectively known as a botnet, and is then used by threat actors for further targeting with ransomware campaigns and espionage. Cybersecurity firms, researchers, and officials from the United States, Canada, Germany, the Netherlands, and Europol took down 106 servers and remediated nearly 15,000 sites that were infected with the malware.

Impact of the Botnet

Sites infected with SocGholish, which are primarily hosted on WordPress, were widespread and provided everyday services, including restaurants and auto repair shops, according to the Dutch National Police. The botnet, also known as 'FakeUpdates,' is linked to the Russian cybercrime group Evil Corp and provided initial access to other ransomware variants, including DoppelPaymer, WastedLoocker, Hades Ransomware, LockBit, RansomHub, and others, according to Infoblox, which participated in the takedown.

Proofpoint, which also participated in the disruption, described Evil Corp as one of the most prominent cybercrime groups in operation and the 'grandfather' of a threat type that compromises websites and uses TDS to redirect users to malware. Following the takedown, the FBI issued a public service announcement warning about cybercriminals using TDS to break into victim networks for ransomware or other financial scams.

Operation Endgame and Operation Riptide

The law enforcement action was part of Operation Endgame, a multinational effort targeting cybercrime since 2024, and more narrowly for the FBI part of Operation Riptide, an ongoing campaign targeting cybercriminals and the infrastructure and financial networks they use to commit fraud. The operation aimed to disrupt the SocGholish botnet and prevent further malicious activities.

Cybercriminal Tactics

Cybercriminals redirect traffic from sites to bypass firewalls, obscure their activity, identify potential victims, and send them to phishing pages to steal credentials, initiate financial scams, access networks, deliver other malware, and sell access to other cybercriminals, officials said. The disruption of the SocGholish botnet is a significant step in the fight against cybercrime, and authorities will continue to work together to combat these threats.

The takedown of the SocGholish botnet demonstrates the importance of international cooperation in the fight against cybercrime. By working together, authorities can disrupt and dismantle malicious infrastructure, preventing further harm to individuals and organizations. As cyber threats continue to evolve, it is essential for authorities to remain vigilant and adapt their strategies to combat these emerging threats.

In conclusion, the disruption of the SocGholish botnet is a significant achievement in the fight against cybercrime. The operation highlights the importance of international cooperation and the need for continued efforts to combat these threats. As the cyber landscape continues to evolve, it is essential for authorities to remain proactive and adapt their strategies to stay ahead of emerging threats.


Source: CyberScoop

Source: CyberScoop

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free