SocGhoulish is a malware family tracked across 0 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 11, 2025; most recent activity November 11, 2025.
SocGhoulish is a malware family associated with malvertising-driven campaigns that deliver loader components to compromised websites and subsequently execute payloads on victims' systems. Recent reporting ties SocGhoulish-style activity to a RansomHub ransomware incident, where detection was triggered by unusual CPU activity, illustrating its role as a delivery/loader mechanism for ransomware. The family is significant due to its broad distribution surface via compromised sites and its ability to deploy second-stage payloads with minimal user interaction.