Police in Europe and North America removed SocGholish malware from nearly 15,000 hacked WordPress websites and took more than 100 related servers and domains offline. Authorities in the Netherlands, Canada, the United States, and Germany said the action targeted the SocGholish botnet, also known as FakeUpdates or GhoLoader, which infects visitors through fake browser-update prompts on compromised sites. Europol and Eurojust said the operation was part of Operation Endgame and disrupted infrastructure linked to the Evil Corp cybercrime group.
2026.06.24
92% relevant
This source also updates the SocGholish/Operation Endgame action, specifying that the broader operation targeted SocGholish alongside Amadey and StealC and noting 14,971 infected websites plus Europol's attribution of SocGholish to Evil Corp-linked criminal activity.
Lawrence Abrams
2026.06.24
86% relevant
This is another Operation Endgame action and adds that the same coordinated campaign disrupted Amadey and StealC infrastructure, affecting 326 servers and 142 domains, recovering 27 million stolen credentials, and again targeting SocGholish/FakeUpdates as part of the broader takedown.
info@thehackernews.com (The Hacker News)
2026.06.19
99% relevant
This is the same Operation Endgame action against SocGholish infrastructure and infected WordPress sites, adding the specific cleaned-site count of 14,971 and reinforcing the server disruption details.
2026.06.19
98% relevant
This article reports the same Operation Endgame takedown of the SocGholish/FakeUpdates infrastructure, adding details on participating countries, domain and server seizures, cleanup of infected WordPress sites, and the malware's use as an access path for ransomware groups including DoppelPaymer, WastedLocker, Hades, LockBit, and RansomHub.
Ionut Arghire
2026.06.19
99% relevant
This article reports the same Operation Endgame event and adds concrete details on SocGholish's role as a JavaScript loader, the count of 14,971 cleaned WordPress sites, 106 seized C2 servers and domains, links to TA569/DEV-0206 and Evil Corp, and examples of follow-on payloads including LockBit, RansomHub, AsyncRAT, and NetSupport RAT.
Sergiu Gatlan
2026.06.18
100% relevant
This article establishes a distinct new story about the June 2026 Operation Endgame action specifically targeting SocGholish-infected WordPress sites and related infrastructure tied to Evil Corp.