Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp

0
Medium
Malwarewebrce
Published: Thu Jun 18 2026 (06/18/2026, 13:25:47 UTC)
Source: Bleeping Computer

Description

International law enforcement agencies have removed SocGholish malware infections from nearly 15,000 WordPress websites and taken down over 100 servers linked to the Evil Corp cybercrime group. SocGholish is a JavaScript-based malware downloader that hijacks legitimate websites to trick visitors into installing fake browser updates, which then give attackers access to infected systems. The malware has been active since at least 2017 and has been used to deploy various other malware families. Authorities advise affected site owners to change credentials, enable multi-factor authentication, delete unknown accounts, and keep WordPress updated. This operation marks a significant disruption to the SocGholish infection chain and the associated cybercriminal infrastructure.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/18/2026, 13:35:32 UTC

Technical Analysis

SocGholish is a JavaScript malware downloader that compromises legitimate WordPress websites to deliver malicious payloads disguised as fake browser updates. Once installed by a victim, it establishes a connection to attackers, enabling remote access and further malware deployment. The malware has been linked to the Russian cybercrime group Evil Corp, known for multiple ransomware and banking malware campaigns. In a coordinated international law enforcement effort involving agencies from the Netherlands, Canada, the US, and Germany, nearly 15,000 infected WordPress sites were cleaned and 106 servers and domains taken offline. The Dutch police removed malware and backdoors from infected sites and recommended security best practices to site owners. This action disrupts a major infection vector used by Evil Corp and limits further damage and spread of malware.

Potential Impact

The SocGholish malware enabled attackers to gain unauthorized access to infected systems by tricking users into installing fake browser updates. This access facilitated deployment of additional malware families, potentially leading to data theft, system compromise, and further cyberattacks. The widespread infection of nearly 15,000 WordPress sites posed a significant risk to visitors and the broader internet ecosystem. The takedown and cleaning of these sites reduce the risk of ongoing exploitation and propagation of malware linked to Evil Corp.

Mitigation Recommendations

Law enforcement agencies have already cleaned the infected WordPress sites and taken down associated servers, significantly disrupting the threat. Website owners are advised to change all credentials, enable multi-factor authentication, remove unknown WordPress accounts, and keep their WordPress installations up to date to prevent reinfection. No additional immediate action is required beyond these recommended security practices.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.bleepingcomputer.com/news/security/law-enforcement-nukes-socgholish-malware-from-nearly-15-000-sites/","fetched":true,"fetchedAt":"2026-06-18T13:35:19.104Z","wordCount":656}

Threat ID: 6a33f417f198dc38c1e14960

Added to database: 6/18/2026, 1:35:19 PM

Last enriched: 6/18/2026, 1:35:32 PM

Last updated: 6/18/2026, 7:11:58 PM

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses