www.truesec.com Operation Endgame Disrupts Evil Corp's SocGholish Malware Network
Article Content
- •Operation Endgame remediated 14,971 infected websites and took down 106 servers.
- •SocGholish malware, linked to Evil Corp, uses fake software updates to compromise systems.
- •The operation involved international cooperation from law enforcement agencies across multiple countries.
On June 18, 2026, international law enforcement agencies launched Operation Endgame, disrupting the SocGholish malware infrastructure linked to the Russian cybercrime group Evil Corp. The operation resulted in the remediation of 14,971 infected WordPress websites and the takedown of 106 servers and domains associated with the SocGholish botnet. SocGholish, also known as FakeUpdates, exploits compromised legitimate websites to deliver malware disguised as fake software updates, targeting users to gain unauthorized access to their systems. The operation was a collaborative effort involving law enforcement from the Netherlands, Canada, the United States, and Germany, supported by Europol. This action is expected to significantly impact the operations of Evil Corp and its affiliates, limiting their ability to execute further attacks. Authorities have advised website owners to enhance their security measures, including changing credentials and enabling multi-factor authentication.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (67)
Following this threat?
Track WastedLocker, Evil Corp and SocGholish in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…