SocGhoulish Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 11, 2025
Last Seen
November 11, 2025

SocGhoulish is a malware family tracked across 0 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 11, 2025; most recent activity November 11, 2025.

Overview

SocGhoulish is a malware family associated with malvertising-driven campaigns that deliver loader components to compromised websites and subsequently execute payloads on victims' systems. Recent reporting ties SocGhoulish-style activity to a RansomHub ransomware incident, where detection was triggered by unusual CPU activity, illustrating its role as a delivery/loader mechanism for ransomware. The family is significant due to its broad distribution surface via compromised sites and its ability to deploy second-stage payloads with minimal user interaction.

Recent Intelligence Reports

  • How a CPU spike led to uncovering a RansomHub ransomware attack — Bleepingcomputer · November 11, 2025

CVSS v3.1 Breakdown