International Police Operation Dismantles SocGholish Botnet Linked to Evil Corp
A coordinated international law enforcement operation has dismantled a major component of the SocGholish malware network, removing infections from nearly 15,000 compromised WordPress websites and taking more than 100 servers and domains offline. The joint action, carried out under the banner of Operation Endgame and supported by Europol and Eurojust, was directed at infrastructure linked to Evil Corp — a prolific Russian cybercrime group active since at least 2007. Participating agencies included the Netherlands’ National High Tech Crime Unit (NHCTU), the Royal Canadian Mounted Police (RCMP), the FBI, and Germany’s Federal Criminal Police Office (BKA).
SocGholish, also tracked as FakeUpdates and GhoLoader, is a JavaScript-based malware downloader that has been used in attacks since at least 2017. The malware operates by hijacking legitimate websites — predominantly those running WordPress — and presenting visitors with convincing fake browser update prompts. When a user installs the fraudulent update, the malware establishes a connection back to attacker-controlled infrastructure, granting persistent access to the victim’s system. Over the years, SocGholish has been used to deploy a wide range of secondary payloads, including the Dridex banking trojan, Doppelpaymer ransomware, and several post-exploitation frameworks.
Dutch police took the lead in scrubbing the malware and backdoors from affected websites, and also issued guidance to site owners: change all credentials, enable multi-factor authentication, remove any unrecognized WordPress administrator accounts, and keep all software up to date. Maikel Rollman of the NHCTU described the action as limiting both the spread of malware and the risk that compromised systems could be weaponized against critical infrastructure. He also signaled that this operation represents an opening move rather than a conclusion, stating that further action against SocGholish is planned.
Evil Corp has previously been sanctioned by the U.S. Treasury’s Office of Foreign Assets Control and has been linked to numerous ransomware strains over the years, including WastedLocker, Hades, Macaw Locker, and Phoenix CryptoLocker. Operation Endgame has now targeted multiple major botnet and loader operations across several phases, previously dismantling infrastructure associated with Rhadamanthys, VenomRAT, Elysium, Smokeloader, DanaBot, IcedID, Pikabot, Trickbot, Bumblebee, and SystemBC.