Visualização de leitura

Operation Endgame Disrupts SocGholish, StealC Malware Networks

Operation Endgame Disrupts SocGholish

Operation Endgame has dealt another blow to cybercriminal operations after international law enforcement agencies and private sector partners dismantled infrastructure supporting the SocGholish, Amadey, and StealC malware families. The coordinated operation resulted in the seizure of more than EUR 41 million in criminal cryptocurrency assets, the recovery of 27 million stolen login credentials, and the disruption of hundreds of servers and domains used to distribute malware.

Led by Europol and Eurojust, the operation brought together authorities from Canada, Denmark, Germany, the Netherlands, the United Kingdom, the United States, Microsoft, and several cybersecurity organizations. Officials said the objective was to disrupt the infrastructure cybercriminals rely on to launch ransomware attacks, financial fraud, and attacks against critical infrastructure.

Operation Endgame Targets Cybercrime Infrastructure

During the coordinated action, authorities targeted the infrastructure supporting malware delivery rather than focusing on a single malware family.

Law enforcement and industry partners took action against 326 servers and 142 domains, significantly disrupting malware distribution channels. Investigators also identified and restricted criminal cryptocurrency assets currently valued at more than EUR 41 million (USD 47 million) while recovering approximately 27 million stolen login credentials.

According to Europol, the operation aimed to disrupt the "assembly line" used by cybercriminals to gain initial access to victim systems before deploying ransomware or stealing sensitive information.

[caption id="attachment_112936" align="aligncenter" width="600"]Operation Endgame Image Soure: Europol[/caption] [caption id="attachment_112937" align="aligncenter" width="600"]Operation Endgame Strikes Malware Image Source: Europol[/caption]

SocGholish, Amadey and StealC Malware Played Different Roles

The operation focused on three malware families that are commonly offered under the cybercrime-as-a-service model.

  • SocGholish functioned as a malware loader that distributed fake browser updates through compromised WordPress websites. Users who installed these fake updates unknowingly infected their systems, allowing attackers to gain initial access and later deploy ransomware or other malicious tools.
  • StealC malware primarily targeted sensitive information stored on infected devices, including passwords, authentication data, and digital identities. The stolen information was later used for fraud or traded within cybercriminal marketplaces.
  • Amadey was mainly distributed through phishing campaigns. It provided attackers with initial access to compromised systems while also offering information-stealing capabilities that enabled the theft of sensitive user data.

Microsoft reported that during the first two weeks of May 2026 alone, Amadey and StealC malware were linked to more than 140,000 infected computers worldwide.

Thousands of Infected WordPress Sites Cleaned

One of the largest actions under Operation Endgame targeted SocGholish, also known as FakeUpdates.

Authorities remediated 14,971 infected WordPress websites, including websites belonging to restaurants, automotive repair businesses, and other organizations. Investigators also disabled the SocGholish botnet by taking control of domains and shutting down supporting servers.

Website owners whose credentials had been exposed were notified through platforms including Have I Been Pwned, DIVD, Spamhaus, CheckjeHack, NoMoreLeaks, Shadowserver, and NL-NCSC.

The Dutch Police urged WordPress administrators to change passwords, enable multi-factor authentication, remove unknown administrator accounts, and keep their websites updated to reduce future compromise risks.

SocGholish Linked to Evil Corp

Authorities said SocGholish has been linked to Evil Corp, a Russian cybercriminal group previously associated with the Zeus and Dridex malware families, as well as multiple ransomware and money laundering operations.

Rather than targeting only malware operators, investigators focused on disrupting the broader infrastructure supporting cybercriminal activity. Europol said this strategy increases operational costs for threat actors and makes large-scale cyberattacks more difficult to execute.

Europol Coordinates Global Cyber Operation

Europol's European Cybercrime Centre (EC3) coordinated operational intelligence sharing through SIENA while providing analytical, technical, and cryptocurrency tracing support throughout the investigation.

The operation forms part of Operation Endgame, described by Europol as the largest international initiative to disrupt ransomware enablers worldwide.

Officials said the latest disruption reflects a growing international strategy of targeting the infrastructure that enables cybercrime operations, rather than responding only after attacks have occurred.

Europol Disrupts StealC and Amadey Malware Infrastructure in Operation Endgame

Operation Endgame disrupted malware services like StealC and Amadey that enable ransomware, fraud, and attacks on critical infrastructure.

Between June 15 and 19, 2026, Europol coordinated a two-week law enforcement operation involving agencies from Canada, Denmark, Germany, the Netherlands, the UK, and the US, alongside private firms like Microsoft, Bitdefender, IBM X-Force, Proofpoint, Infoblox, Shadowserver, Orange Cyberdefense, and a dozen other private partners.

The operation targeted the infrastructure behind three malware families, SocGholish, Amadey, and StealC, that together form the opening stages of the cybercrime attack chain.

“The main common goal was to disrupt the “assembly lines” cybercriminals use to launch ransomware, financial fraud, and attacks on critical infrastructure.” reads the report published by EUROPOL. “Crypto assets of criminal origin currently valued at over EUR 41 million (USD 47 million) were identified, flagged, and thereby restricted from use. “

The numbers from the action are substantial. Law enforcement and private partners actioned 326 servers and 142 domains, recovered 27 million stolen login credentials, and identified, flagged, and restricted over €41 million in criminal cryptocurrency assets.

During the SocGholish portion of the operation, 14,971 infected websites were remediated, including restaurants, auto repair shops, and other everyday businesses whose WordPress installations had been quietly compromised and turned into malware distribution points. The Dutch Police removed vulnerabilities from infected sites and notified owners directly.

SocGholish works by injecting fake browser update prompts into legitimate websites. A visitor clicks what looks like a routine update, and the malware installs.

“This approach, which has caused countless victims, is primarily done by hacking websites built with WordPress and infecting them with malware.” continues the report.” The unauthorised access was then exploited for further crimes, such as installing ransomware for the purpose of digital extortion.”

SocGholish is linked to Evil Corp, the Russian cybercriminal group previously responsible for Zeus and Dridex, and associated with multiple large-scale ransomware and money-laundering operations.

Amadey has been running since October 2018 as a paid dropper service, spreading primarily through phishing campaigns. It gains initial access, delivers additional malware, and also has credential and clipboard stealing capabilities. StealC, which surfaced in January 2023, is the harvesting layer: it pulls passwords, stored credentials, digital identities, and sensitive data from compromised machines and makes them available for resale and fraud.

“Amadey gains initial access to devices, while StealC extracts passwords and sensitive data.” states the report. “Together, they form a critical link in the cybercrime supply chain.”

Microsoft linked both families to over 140,000 infected computers worldwide in just the first two weeks of May 2026.

The operational logic behind targeting these three families simultaneously is what makes this phase of Operation Endgame strategically significant. Rather than focusing on the ransomware payload at the end of the chain, the operation hit the tools that make every subsequent stage possible.

“Operation Endgame targets the initial access malware used to infect devices. Cybercriminals use this malware as a gateway to silently infiltrate victims’ systems and steal sensitive data.” reads the press release published by EuroJust. “By fighting the initial stage of the attack chain, the operation strikes at the heart of the entire ‘cybercrime-as-a-service’ ecosystem.”

Take out the loader, and the ransomware operator has no foothold to monetize.

Victim notifications went out through HaveIBeenPwned, DIVD, Spamhaus, CheckjeHack, NoMoreLeaks, Shadowserver, and the Dutch National Cyber Security Centre. WordPress site owners whose credentials were leaked have been urged to change login credentials, enable multi-factor authentication, delete any unknown admin accounts, and keep their installations updated. For ordinary users, the advice on SocGholish is the same it’s always been and apparently still needs repeating: genuine software updates come from official sources through system settings or app stores, not from browser pop-ups that scream for immediate action.

Operation Endgame is described by Europol as the largest international operation ever undertaken to tackle ransomware enablers worldwide. More than 30 public and private parties support its actions on an ongoing basis.

The operation has an active suspect portal. The message from every law enforcement statement is consistent: each takedown raises costs, degrades operations, and generates intelligence for the next one.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Operation Endgame)

14,971 WordPress Sites Cleaned in Global SocGholish Takedown

Operation EndGame disrupted SocGholish, taking down 106 servers and cleaning 14,971 WordPress sites used to spread fake-update malware.

On June 18, 2026, law enforcement agencies from the Netherlands, Canada, the United States, and Germany, coordinated through Europol, executed a joint action week against SocGholish, one of the most persistent and widely deployed malware distribution networks on the internet.

The Operation EndGame took down over 100 servers and domains and removed infections from 14,971 compromised WordPress websites. Proofpoint, which has tracked the group behind SocGholish since 2018, provided intelligence to support the law enforcement actions.

“In the past few days, the Netherlands (NHCTU), Canada (RCMP), the United States (FBI) and Germany (BKA), with support from Europol and Eurojust, delivered a major blow to SocGholish’s criminal infrastructure during a joint action week.” reads the press release.

“Worldwide, 106 servers and domains were taken down. 14.971 websites have been remediated. In addition, the following actions were carried out:

  • Cleaning infected WordPress sites and victim notification, urging previously infected WordPress owners to update their sites and change their login credentials.
  • Disabling the SocGholish botnet by taking over domain names and taking servers offline.
  • Victim notification for owners of WordPress sites whose leaked login credentials were identified by the police, via HaveIBeenPwned, DIVD, Spamhaus, CheckjeHack, NoMoreLeaks, The Shadowserver Foundation and NCSC (Netherlands).”

SocGholish, also known as FakeUpdates, is operated by a threat group Proofpoint tracks as TA569. The technique is elegantly simple and devastatingly effective: compromise a legitimate website, inject malicious JavaScript, and when a visitor arrives and passes a set of filtering checks, overwrite the entire page with a convincing fake browser update prompt.

“TA569 is one of the most prominent cybercriminal threat groups in Proofpoint threat data, which our researchers have tracked since 2018.” reads Proofpoint’s report. “TA569’s SocGholish inject activity has been linked to major ransomware families and criminal syndicates.”

Those families include WastedLocker, LockBit, and RansomHub. TA569 acts as an initial access broker, and public reporting has linked it to Evil Corp, the Russian cybercriminal group whose members have been sanctioned multiple times by Western governments.

The scale of the problem before the takedown was substantial. In May 2026, ShadowServer found more than 1.44 million compromised WordPress websites available for use by SocGholish. Infoblox reported that approximately 55% of cloud customers had been exposed to SocGholish this year.

“The outcomes included:

  • 14,971 compromised legitimate WordPress sites infected with SocGholish malware remediatedreads the report by ShadowServer.
  • 106 servers and domains taken down worldwide, disrupting the SocGholish botnet”

TA569 compromised sites across virtually every sector: nonprofits, schools, hospitals, legal firms, real estate companies, and major media and retail portals visited by millions of users daily.

Getting into those sites is less spectacular than it sounds. TA569 and its partners gain access through password spraying, stolen or reused credentials, vulnerabilities in WordPress plugins and themes, and weaknesses in third-party dependencies.

“These attacks often target outdated components, but they are not limited to known vulnerabilities. Attackers may also exploit zero-days, abandoned plugins, custom templates, or third-party dependencies that are no longer maintained. In some cases, plugin or theme developers may not realize that underlying libraries or bundled components used by their products also need security updates.” continues Proofpoint. “This can leave sites exposed even when the CMS core appears to be current.”

Once inside, the operator establishes persistence through multiple mechanisms: added admin accounts, PHP backdoors placed outside the CMS directory structure, and fake plugins with benign-sounding names that hide themselves from the WordPress admin interface. Cleaning up visible malware without finding the persistence mechanism is a common mistake that results in reinfection within days.

The delivery chain has grown more sophisticated over time. In the current configuration, TA569 works with TA2726, which operates a malicious version of the Keitaro traffic distribution service (TDS). TA2726 injects highly obfuscated JavaScript into compromised sites via a fake WordPress plugin, which eventually loads the SocGholish code. Stage 1 of SocGholish then profiles the visitor: it checks for automated browsers, open developer tools, prior visits to the fake update page, and WordPress admin sessions. It also waits for the mouse to move at least ten times before proceeding. If the visitor passes all checks, the malware overwrites the entire page.

“Even though the download button might look basic, it’s actually advanced. Clicking it sends a ”postMessage” to a separate hidden iframe that was loaded from a “data:” URI. That iframe fetches a script from the TA569 C2 which contains the file “Google Launcher.js” (GhoLoader Stage 1, C2: “js-new[.]newtoyourgame[.]com”) as an embedded base64 blob, constructs it client-side via “URL.createObjectURL()”, and triggers the download.” continues the report. “This means the downloaded file originates from a “blob:” URL with no direct network download trace pointing to a malicious JavaScript file. Sandboxes that simply “.click()” the button without proper cross-frame message handling will never trigger the download at all.”

The downloaded file is GhoLoader Stage 1, a WSH JScript that communicates with its C2 and executes the response. Sandboxes that simply click the button without handling cross-frame messages won’t trigger the download at all.

Orange Cyber Defense’s CERT observed SocGholish delivering loaders, including GhoLoader and MintsLoader that led to GhostWeaver PowerShell backdoor, LockBit and RansomHub ransomware, and AsyncRAT and NetSupport RAT. The Dutch police noted that notifications were also sent to WordPress site owners whose compromised credentials were identified in the operation, urging them to change logins, enable MFA, delete suspect accounts, and update their software.

The operation will have a significant impact, but it won’t end the web inject problem. TA569 may be, as Proofpoint put it, the originator of the technique, but the web inject space has expanded well beyond a single actor.

“What went from being a technique only used by a handful of threat actors – popularized and innovated by TA569 – web injects have become a common technique used by numerous threat clusters beyond the TA569 ecosystem including ClearFake, ZPHP, and ErrTraffic.” concludes the report.

Proofpoint tracks nearly a dozen distinct threat clusters running web inject campaigns, and the technique has been rising consistently since 2023. TA2726, the TDS provider that funneled traffic for TA569, was not directly targeted in the operation and will continue operating. Its traffic currently also serves TA2727, which delivers different payloads to MacOS users, including FrigidStealer.

For WordPress administrators, the Dutch police and Proofpoint both published concrete remediation steps: enable MFA for all admin accounts, restrict wp-admin access by IP allowlist, remove unused plugins and themes, block PHP execution in the uploads directory, enable file integrity monitoring, and assume that if a site was previously infected, the credentials used to access it are compromised.

Cleaning only the injected code while leaving stale admin accounts and unchanged passwords is not remediation. It’s just delay.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Operation EndGame)

Operation Endgame Hits SocGholish Malware Network, 14,971 Websites Cleaned

SocGholish Malware

Operation Endgame Hits SocGholish Malware Network after international law enforcement agencies carried out a coordinated operation targeting one of the most significant malware distribution chains linked to cybercrime. Authorities announced the remediation of 14,971 websites infected with SocGholish Malware, a threat used by the cybercriminal group Evil Corp to gain unauthorized access to victim systems and facilitate further attacks. The operation involved law enforcement agencies from the Netherlands, Canada, the United States, and Germany, with support from Europol and Eurojust. Officials described the action as a major disruption of the infrastructure used to distribute malware through compromised WordPress websites.

Operation Endgame Hits SocGholish Malware Network Across Multiple Countries

During the coordinated action week, authorities took down 106 servers and domains associated with the criminal infrastructure supporting SocGholish operations. According to investigators, SocGholish Malware spreads primarily through compromised WordPress websites. Visitors to infected websites are presented with fake software update prompts, often disguised as browser updates. Once downloaded and installed, the malware establishes access to the victim's system, allowing attackers to deploy additional malicious software. Law enforcement agencies also disabled the SocGholish Botnet by seizing domains and taking servers offline. In addition to infrastructure takedowns, authorities cleaned infected WordPress sites and launched a large-scale victim notification campaign to warn affected website owners and encourage stronger security measures.

WordPress Websites at the Center of the Campaign

Authorities highlighted the widespread use of WordPress as a factor contributing to the scale of the threat. According to WordPress, more than 43% of websites worldwide are built on the platform. Investigators reported that login credentials for approximately 1.4 million websites have been leaked, increasing the risk of unauthorized access and malware infections. Cybercriminals behind SocGholish typically compromise websites by exploiting weak passwords, stolen credentials, or vulnerable website configurations. Once access is obtained, malicious code is inserted into websites, allowing attackers to distribute fake updates to visitors. The infected websites included platforms providing everyday services, such as restaurants and automotive repair businesses.

Authorities Urge Website Owners to Strengthen Security

The Dutch National High Tech Crime Unit stated that malware and backdoors have been removed from affected websites and that site owners have been notified. Website owners have been urged to: Authorities emphasized that these measures can significantly reduce the likelihood of future compromise.

Fake Updates Continue to Drive Infections

Also known as FakeUpdates, SocGholish has remained active since 2017 and continues to be used as an initial access tool for broader cybercriminal operations. The malware is distributed through fraudulent software update messages that appear while users browse compromised websites. Once installed, the malware creates a connection to attackers, enabling them to gain access to victim systems. Officials warned users not to trust browser pop-ups requesting immediate software updates and advised obtaining updates only through official application stores, system settings, or verified vendors. Additional recommendations include maintaining updated antivirus software and exercising caution when encountering urgent update notifications. Law enforcement agencies linked Evil Corp to the SocGholish malware operation. The group has previously been associated with Zeus and Dridex malware campaigns, as well as multiple ransomware and money laundering operations. Authorities noted that SocGholish has been used to deploy various ransomware strains that have impacted organizations and critical infrastructure targets worldwide.

Operation Endgame Expands Global Cybercrime Disruption Efforts

Launched in 2024, Operation Endgame is described by participating agencies as the largest international effort to combat ransomware and cybercrime. The initiative brings together law enforcement and judicial authorities from the Netherlands, Germany, Denmark, the United States, Australia, France, Belgium, the United Kingdom, and Canada, with support from Europol and Eurojust. Officials stated that cooperation between public agencies and private-sector cybersecurity organizations remains a critical component of the operation as efforts continue against SocGholish and other cybercriminal networks.
❌