Police Clean Nearly 15,000 SocGholish-Infected Sites Tied to Evil Corp

Under Operation Endgame, international law enforcement cleaned 14,971 WordPress sites infected by the SocGholish downloader and took 106 servers and domains offline, in a coordinated action by the Netherlands NHCTU, Canada’s RCMP, the US FBI, and Germany’s BKA with Europol/Eurojust support. The operation targets Evil Corp-linked activity and aims to curb further infections by removing backdoors and advising site owners to reset credentials, enable MFA, and keep WordPress up to date. SocGholish has operated since 2017, delivering malware via fake browser updates.

TechLogHub
June 18, 2026
4 min read
0 views

Share Article

Police Clean Nearly 15,000 SocGholish-Infected Sites Tied to Evil Corp

Operation Endgame: Law Enforcement Dismantles SocGholish Infrastructure

OverviewA coordinated international operation has disrupted a major infection chain used by the Evil Corp cybercrime group. In a joint effort supported by Europol and Eurojust, authorities conducted a wide-ranging takedown that touched thousands of WordPress sites and more than a hundred command-and-control servers. The initiative aimed to sever the infrastructure behind the SocGholish malware downloader, disrupt ongoing attacks, and hamper the spread of additional payloads deployed by the group.

Scope and Impact

  • Malware-infected sites cleaned: 14,971 compromised WordPress sites identified and cleaned of SocGholish contaminants.
  • Servers disabled: 106 servers and domains offline, severing critical control points used by the attackers.
  • International reach: Actions coordinated among law enforcement teams from the Netherlands, Canada, the United States, and Germany.
  • Supporting agencies: The operation was carried out with backing from national high-tech crime units and international partners, leveraging information sharing and joint seizure efforts to maximize impact.

How SocGholish Works

  • Nature of the threat: SocGholish is a JavaScript-based malware downloader, also known in the ecosystem as FakeUpdates and GhoLoader. It hijacks legitimate websites—primarily WordPress sites—and deceives visitors into executing malicious updates.
  • Infection chain: When a visitor interacts with a compromised page and unwittingly installs a malicious update, the malware connects back to attacker-controlled infrastructure, granting remote access to the infected system.
  • Payload delivery: The downloader is used to deploy a variety of malicious payloads, often masqueraded as software updates or browser components.
  • Historical footprint: SocGholish operations have been active since at least 2017, demonstrating persistence and a willingness to evolve tactics over time.
  • Associated malware families: Beyond initial downloaders, SocGholish has served as a delivery mechanism for other threats, including Dridex, Doppelpaymer, Empire, Koadic, Chtonic, and Azorult. This versatility makes the campaign a persistent risk vector for Windows environments and other targets.

The Evil Corp Nexus

  • Group identity: Evil Corp is a Russian cybercrime collective linked to a long-running history of financially motivated campaigns. The operation has connections to legacy threats such as Zeus and Dridex and has been implicated in multiple ransomware and data-theft campaigns.
  • Ransomware and related activities: Prior campaigns attributed to Evil Corp have included WastedLocker, Hades, Macaw Locker, and Phoenix CryptoLocker, illustrating a pattern of leveraging sophisticated infection chains to enable broader criminal activities.
  • Strategic objective: By controlling delivery mechanisms like SocGholish, Evil Corp can stage attacks against critical infrastructure, financial institutions, and other high-value targets with greater stealth and reach.

Key Statements from Authorities

  • Official framing: Authorities described the operation as a strategic strike aimed at depriving cybercriminals of access to compromised systems, reducing the likelihood of subsequent attacks, and limiting the spread of malware across digital ecosystems.
  • National context: The Dutch National High Tech Crime Unit and its international partners framed the takedown as the beginning of a broader offensive against SocGholish, signaling ongoing efforts to dismantle the group's infrastructure and disrupt its operational capabilities.

Technical and Operational Takeaways

  • Targeting the infrastructure: The focus was on cutting off the access points used by SocGholish to deliver payloads, including takedowns of servers and domain registrations that hosted malicious components.
  • Infected website cleanup: Cleaning the infected WordPress sites involved removing malware code, backdoors, and any remnants that could facilitate reinfection or persistence.
  • Credential hygiene and access controls: In the wake of takedowns, authorities emphasized the importance of strong credentials, multi-factor authentication, and routine updates to curb the risk of re-compromise.
  • The role of proactive defense: The operation underscores the value of threat intelligence sharing and cross-border collaboration in neutralizing sophisticated, evolving threat campaigns that leverage widely used platforms like WordPress.

Operational Context and Media

  • Visual assets: Illustrative material associated with Operation Endgame accompanied press releases and security briefings, highlighting the scope of the action and the scale of the disruption.
  • Related threat landscape: The SocGholish campaign sits within a broader ecosystem of malware delivery mechanisms that leverage compromised websites and trusted software distribution tropes, illustrating how attackers blend social engineering with technical subterfuge to maximize reach.

Security Posture and Observations

  • Attack surface dynamics: The use of compromised legitimate sites as initial footholds demonstrates how attackers exploit trust in web infrastructure to seed infections.
  • Defense integration: The incident reinforces the need for layered security controls on web properties, including rigorous site hygiene, regular software updates, malware scanning, and continuous monitoring for unusual modifications.
  • Incident response implications: Coordinated international actions can rapidly disrupt infection chains, but long-term resilience requires ongoing vigilance, collaboration, and remediation across affected domains.

Contextual Links and Related Themes

  • The operation is part of a continuing series of actions against prominent cybercrime operations, reflecting a sustained effort to degrade the capabilities of high-profile groups and to interdict their supply chains.
  • The SocGholish paradigm continues to influence how defenders think about software update vectors, supply-chain hygiene, and the importance of safeguarding website ecosystems that host large audiences.

ConclusionOperation Endgame marks a significant milestone in disrupting the SocGholish infection chain and the broader Evil Corp ecosystem. By cleaning thousands of WordPress sites and taking offline more than a hundred infrastructure nodes, international law enforcement signals a sustained, coordinated approach to combating sophisticated cybercriminal networks. The campaign illustrates how the convergence of technical takedowns, cross-border cooperation, and proactive site defense can reduce the attacker’s footprint and limit the potential damage from future campaigns. The authorities portrayed this as the opening phase of a broader offensive, with ongoing efforts to identify, investigate, and neutralize remaining assets tied to SocGholish and its associated criminal network.

Stay Updated

Get the next deep dive in your inbox

Subscribe for product analysis, engineering explainers, and practical guides published on TechLogHub.

See what launched this week

One email a week: new and trending developer tools, fresh comparisons, and what shipped. Unsubscribe in one click.

Police Clean Nearly 15,000 SocGholish-Infected Sites Tied to Evil Corp | TechLogHub