Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group. [...]
AI Analysis
Technical Summary
SocGholish is a JavaScript malware downloader that compromises legitimate WordPress websites to deliver malicious payloads disguised as fake browser updates. Once installed by a victim, it establishes a connection to attackers, enabling remote access and further malware deployment. The malware has been linked to the Russian cybercrime group Evil Corp, known for multiple ransomware and banking malware campaigns. In a coordinated international law enforcement effort involving agencies from the Netherlands, Canada, the US, and Germany, nearly 15,000 infected WordPress sites were cleaned and 106 servers and domains taken offline. The Dutch police removed malware and backdoors from infected sites and recommended security best practices to site owners. This action disrupts a major infection vector used by Evil Corp and limits further damage and spread of malware.
Potential Impact
The SocGholish malware enabled attackers to gain unauthorized access to infected systems by tricking users into installing fake browser updates. This access facilitated deployment of additional malware families, potentially leading to data theft, system compromise, and further cyberattacks. The widespread infection of nearly 15,000 WordPress sites posed a significant risk to visitors and the broader internet ecosystem. The takedown and cleaning of these sites reduce the risk of ongoing exploitation and propagation of malware linked to Evil Corp.
Mitigation Recommendations
Law enforcement agencies have already cleaned the infected WordPress sites and taken down associated servers, significantly disrupting the threat. Website owners are advised to change all credentials, enable multi-factor authentication, remove unknown WordPress accounts, and keep their WordPress installations up to date to prevent reinfection. No additional immediate action is required beyond these recommended security practices.
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
Description
International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group. [...]
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
SocGholish is a JavaScript malware downloader that compromises legitimate WordPress websites to deliver malicious payloads disguised as fake browser updates. Once installed by a victim, it establishes a connection to attackers, enabling remote access and further malware deployment. The malware has been linked to the Russian cybercrime group Evil Corp, known for multiple ransomware and banking malware campaigns. In a coordinated international law enforcement effort involving agencies from the Netherlands, Canada, the US, and Germany, nearly 15,000 infected WordPress sites were cleaned and 106 servers and domains taken offline. The Dutch police removed malware and backdoors from infected sites and recommended security best practices to site owners. This action disrupts a major infection vector used by Evil Corp and limits further damage and spread of malware.
Potential Impact
The SocGholish malware enabled attackers to gain unauthorized access to infected systems by tricking users into installing fake browser updates. This access facilitated deployment of additional malware families, potentially leading to data theft, system compromise, and further cyberattacks. The widespread infection of nearly 15,000 WordPress sites posed a significant risk to visitors and the broader internet ecosystem. The takedown and cleaning of these sites reduce the risk of ongoing exploitation and propagation of malware linked to Evil Corp.
Mitigation Recommendations
Law enforcement agencies have already cleaned the infected WordPress sites and taken down associated servers, significantly disrupting the threat. Website owners are advised to change all credentials, enable multi-factor authentication, remove unknown WordPress accounts, and keep their WordPress installations up to date to prevent reinfection. No additional immediate action is required beyond these recommended security practices.
Technical Details
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/law-enforcement-nukes-socgholish-malware-from-nearly-15-000-sites/","fetched":true,"fetchedAt":"2026-06-18T13:35:19.104Z","wordCount":656}
Threat ID: 6a33f417f198dc38c1e14960
Added to database: 06/18/2026, 13:35:19 UTC
Last enriched: 06/18/2026, 13:35:32 UTC
Last updated: 08/01/2026, 04:26:26 UTC
Views: 183
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.