Operation Endgame removes SocGholish malware from nearly 15,000 WordPress sites and seizes 106 servers tied to Evil Corp

Police in Europe and North America removed SocGholish malware from nearly 15,000 hacked WordPress websites and took more than 100 related servers and domains offline. Authorities in the Netherlands, Canada, the United States, and Germany said the action targeted the SocGholish botnet, also known as FakeUpdates or GhoLoader, which infects visitors through fake browser-update prompts on compromised sites. Europol and Eurojust said the operation was part of Operation Endgame and disrupted infrastructure linked to the Evil Corp cybercrime group.
Why it matters: This cuts off a long-running malware infection path that has been used to infect everyday web visitors and deliver other crimeware and ransomware. WordPress site owners should check for compromise, rotate credentials, enable multi-factor authentication, and remove unknown accounts; users should avoid software update prompts shown on random websites.

Sources

Three ‘cybercrime as a service’ operations undercut by Microsoft, law enforcement
2026.06.24 92% relevant
This source also updates the SocGholish/Operation Endgame action, specifying that the broader operation targeted SocGholish alongside Amadey and StealC and noting 14,971 infected websites plus Europol's attribution of SocGholish to Evil Corp-linked criminal activity.
Amadey, StealC malware operations disrupted in Operation Endgame action
Lawrence Abrams 2026.06.24 86% relevant
This is another Operation Endgame action and adds that the same coordinated campaign disrupted Amadey and StealC infrastructure, affecting 326 servers and 142 domains, recovering 27 million stolen credentials, and again targeting SocGholish/FakeUpdates as part of the broader takedown.
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
info@thehackernews.com (The Hacker News) 2026.06.19 99% relevant
This is the same Operation Endgame action against SocGholish infrastructure and infected WordPress sites, adding the specific cleaned-site count of 14,971 and reinforcing the server disruption details.
Police raid malware network tied to Russia's Evil Corp hacker group
2026.06.19 98% relevant
This article reports the same Operation Endgame takedown of the SocGholish/FakeUpdates infrastructure, adding details on participating countries, domain and server seizures, cleanup of infected WordPress sites, and the malware's use as an access path for ransomware groups including DoppelPaymer, WastedLocker, Hades, LockBit, and RansomHub.
15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown
Ionut Arghire 2026.06.19 99% relevant
This article reports the same Operation Endgame event and adds concrete details on SocGholish's role as a JavaScript loader, the count of 14,971 cleaned WordPress sites, 106 seized C2 servers and domains, links to TA569/DEV-0206 and Evil Corp, and examples of follow-on payloads including LockBit, RansomHub, AsyncRAT, and NetSupport RAT.
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
Sergiu Gatlan 2026.06.18 100% relevant
This article establishes a distinct new story about the June 2026 Operation Endgame action specifically targeting SocGholish-infected WordPress sites and related infrastructure tied to Evil Corp.
← Back to all stories