Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
International law enforcement agencies have removed SocGholish malware infections from nearly 15,000 WordPress websites and taken down over 100 servers linked to the Evil Corp cybercrime group. SocGholish is a JavaScript-based malware downloader that hijacks legitimate websites to trick visitors into installing fake browser updates, which then give attackers access to infected systems. The malware has been active since at least 2017 and has been used to deploy various other malware families. Authorities advise affected site owners to change credentials, enable multi-factor authentication, delete unknown accounts, and keep WordPress updated. This operation marks a significant disruption to the SocGholish infection chain and the associated cybercriminal infrastructure.
AI Analysis
Technical Summary
SocGholish is a JavaScript malware downloader that compromises legitimate WordPress websites to deliver malicious payloads disguised as fake browser updates. Once installed by a victim, it establishes a connection to attackers, enabling remote access and further malware deployment. The malware has been linked to the Russian cybercrime group Evil Corp, known for multiple ransomware and banking malware campaigns. In a coordinated international law enforcement effort involving agencies from the Netherlands, Canada, the US, and Germany, nearly 15,000 infected WordPress sites were cleaned and 106 servers and domains taken offline. The Dutch police removed malware and backdoors from infected sites and recommended security best practices to site owners. This action disrupts a major infection vector used by Evil Corp and limits further damage and spread of malware.
Potential Impact
The SocGholish malware enabled attackers to gain unauthorized access to infected systems by tricking users into installing fake browser updates. This access facilitated deployment of additional malware families, potentially leading to data theft, system compromise, and further cyberattacks. The widespread infection of nearly 15,000 WordPress sites posed a significant risk to visitors and the broader internet ecosystem. The takedown and cleaning of these sites reduce the risk of ongoing exploitation and propagation of malware linked to Evil Corp.
Mitigation Recommendations
Law enforcement agencies have already cleaned the infected WordPress sites and taken down associated servers, significantly disrupting the threat. Website owners are advised to change all credentials, enable multi-factor authentication, remove unknown WordPress accounts, and keep their WordPress installations up to date to prevent reinfection. No additional immediate action is required beyond these recommended security practices.
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
Description
International law enforcement agencies have removed SocGholish malware infections from nearly 15,000 WordPress websites and taken down over 100 servers linked to the Evil Corp cybercrime group. SocGholish is a JavaScript-based malware downloader that hijacks legitimate websites to trick visitors into installing fake browser updates, which then give attackers access to infected systems. The malware has been active since at least 2017 and has been used to deploy various other malware families. Authorities advise affected site owners to change credentials, enable multi-factor authentication, delete unknown accounts, and keep WordPress updated. This operation marks a significant disruption to the SocGholish infection chain and the associated cybercriminal infrastructure.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
SocGholish is a JavaScript malware downloader that compromises legitimate WordPress websites to deliver malicious payloads disguised as fake browser updates. Once installed by a victim, it establishes a connection to attackers, enabling remote access and further malware deployment. The malware has been linked to the Russian cybercrime group Evil Corp, known for multiple ransomware and banking malware campaigns. In a coordinated international law enforcement effort involving agencies from the Netherlands, Canada, the US, and Germany, nearly 15,000 infected WordPress sites were cleaned and 106 servers and domains taken offline. The Dutch police removed malware and backdoors from infected sites and recommended security best practices to site owners. This action disrupts a major infection vector used by Evil Corp and limits further damage and spread of malware.
Potential Impact
The SocGholish malware enabled attackers to gain unauthorized access to infected systems by tricking users into installing fake browser updates. This access facilitated deployment of additional malware families, potentially leading to data theft, system compromise, and further cyberattacks. The widespread infection of nearly 15,000 WordPress sites posed a significant risk to visitors and the broader internet ecosystem. The takedown and cleaning of these sites reduce the risk of ongoing exploitation and propagation of malware linked to Evil Corp.
Mitigation Recommendations
Law enforcement agencies have already cleaned the infected WordPress sites and taken down associated servers, significantly disrupting the threat. Website owners are advised to change all credentials, enable multi-factor authentication, remove unknown WordPress accounts, and keep their WordPress installations up to date to prevent reinfection. No additional immediate action is required beyond these recommended security practices.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/law-enforcement-nukes-socgholish-malware-from-nearly-15-000-sites/","fetched":true,"fetchedAt":"2026-06-18T13:35:19.104Z","wordCount":656}
Threat ID: 6a33f417f198dc38c1e14960
Added to database: 6/18/2026, 1:35:19 PM
Last enriched: 6/18/2026, 1:35:32 PM
Last updated: 6/18/2026, 7:11:58 PM
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.