International Law Enforcement Disrupts SocGholish (js.fakeupdates) Access-Broker Infrastructure Linked to Evil Corp — Threadlinqs Intelligence
As of 2026-06-18, International Law Enforcement Disrupts SocGholish (js.fakeupdates) Access-Broker Infrastructure Linked to Evil Corp is a high-severity malware threat attributed to Mustard Tempest (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 38 indicators of compromise.
Threat ID: TL-2026-0852 · Severity: HIGH · Status: TRACKING · Category: MALWARE
Attribution: Mustard Tempest · Russia · FINANCIAL
An international law-enforcement coalition (Netherlands NHCTU, Canada RCMP, US FBI, Germany BKA, with Europol and Eurojust) disrupted the SocGholish / js.fakeupdates criminal infrastructure on
On 2026-06-18 the Netherlands National High Tech Crime Unit (NHCTU/Politie NL), the Royal Canadian Mounted Police (RCMP), the U.S. FBI and Germany's BKA, supported by Europol and Eurojust, executed a joint action week against the SocGholish (also tracked as FakeUpdates, malware family js.fakeupdates) criminal infrastructure. The action took down 106 servers and domains worldwide, remediated 14,971 compromised websites, removed backdoors and malware from infected WordPress sites, and notified WordPress owners whose leaked login credentials had been identified — urging them to update their sites and rotate credentials. The disruption is part of the broader Operation Endgame coordinated takedown effort and targets one of the most prolific initial-access loaders in the criminal ecosystem.
SocGholish has been a constant threat since 2017. It is an initial-access broker / loader operated by the threat actor TA569 (also Mustard Tempest, DEV-0206, UNC1543) as a malware-as-a-service offering, selling access to downstream customers including the Russian cybercriminal group Evil Corp (DEV-0243, UNC2165, Manatee Tempest), LockBit, RansomHub, and Dridex/WastedLocker operators. The campaign compromises legitimate websites — frequently WordPress sites with weak or stolen wp-admin credentials — and injects JavaScript that serves fake browser-update lures (Google Chrome, Mozilla Firefox) to visitors via traffic-distribution systems such as Parrot TDS and Keitaro TDS (the latter operated by the affiliate TA2726).
Victims who click the fake update download a JavaScript stager (e.g. Update.js, LatestVersion.js) executed through Windows Script Host (wscript.exe). The loader fingerprints and filters victims — blocking WordPress admins, detecting webdriver/automated browsers, filtering mobile devices, and using an adViewEnabledKey localStorage flag and mouse-movement gating to evade analysis and prevent re-infection. Staging servers generate payloads dynamically at runtime and relay system-information and discovery output staged in TXT files under %AppData%\Local\Temp\. Hands-on-keyboard activity observed includes disabling RestrictedAdmin mode via the registry, PowerSharpPack UrbanBishop process injection for credential harvesting, and lateral movement over RDP and WMIC, with the typical final objective being ransomware deployment. Proxy-fronted C2 routes to backend infrastructure (including Tor), domains rotate every 2-3 days, and domain-shadowing on compromised registrar accounts is used to stand up disposable subdomains.
Target sectors: government, critical infrastructure, financial, healthcare, media, manufacturing, transportation
Target regions: North America, Europe, Global
Detections & IOCs
As of 2026-08-17, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 38 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1586, T1583, T1608, T1189, T1566, T1078, T1059, T1204, T1078, T1055