Operation Endgame Disrupts Evil Corp's SocGholish Malware Network

Operation Endgame Disrupts Evil Corp's SocGholish Malware Network

First seen 18 Jun 2026, 12:57 UTC Proofpointwww.politie.nlwww.truesec.comBleepingcomputerFeeds2.Feedburner+49 86% similarity 78.0

Article Content

Browse articles
ThreatCluster

On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the remediation of 14,971 infected WordPress websites and the takedown of 106 servers and domains associated with the SocGholish botnet. SocGholish, also known as FakeUpdates, exploits compromised legitimate websites to deliver malware disguised as fake software updates, targeting users to gain unauthorized access to their systems. The operation was a collaborative effort involving law enforcement from the Netherlands, Canada, the United States, and Germany, supported by Europol. This action is expected to significantly impact the operations of Evil Corp and its affiliates, limiting their ability to execute further attacks. Authorities have advised website owners to enhance their security measures, including changing credentials and enabling multi-factor authentication.

Key Points: • Operation Endgame remediated 14,971 infected websites and took down 106 servers. • SocGholish malware, linked to Evil Corp, uses fake software updates to compromise systems. • The operation involved international cooperation from law enforcement agencies across multiple countries.

ThreatCluster AI How this analysis works

Timeline

2026-06-18
Operation Endgame launched
International law enforcement disrupted the SocGholish malware network, cleaning 14,971 infected sites and taking down 106 servers.
BleepingComputer
2026-06-18
SocGholish malware linked to Evil Corp
Authorities confirmed that SocGholish, also known as FakeUpdates, is operated by the Russian cybercrime group Evil Corp, targeting WordPress sites.
Cyberscoop
2026-06-18
Law enforcement advises website owners
Following the operation, authorities urged website owners to change credentials and implement security measures to prevent future infections.
Heise.De

Community

Browse all →