International Law Enforcement Disrupts SocGholish (js.fakeupdates) Access-Broker Infrastructure Linked to Evil Corp
International Law Enforcement Disrupts SocGholish (TL-2026-0852), also tracked as FakeUpdates, is a high-severity malware campaign, first published 2026-06-18. It is attributed to Mustard Tempest (Russia) with high confidence, affects Automattic / WordPress community WordPress, maps to 21 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 38 indicators of compromise.
Key facts for TL-2026-0852
- Threat ID
- TL-2026-0852
- Also known as
- FakeUpdates, js.fakeupdates, SocGholish takedown, Operation Endgame (SocGholish action week)
- Severity
- HIGH
- Status
- TRACKING
- Category
- MALWARE
- First published
- 2026-06-18
- Last reviewed
- 2026-06-18
- Attribution
- Mustard Tempest
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- FINANCIAL
- Target sectors
- government, critical infrastructure, financial, healthcare, media, manufacturing, transportation
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 38
Malware and tooling in International Law Enforcement Disrupts SocGholish
Malware and tooling: Raspberry Robin, js.fakeupdates, Cobalt Strike, Keitaro TDS, NetSupport RAT, Parrot TDS, PowerSharpPack UrbanBishop
An international law-enforcement coalition (Netherlands NHCTU, Canada RCMP, US FBI, Germany BKA, with Europol and Eurojust) disrupted the SocGholish / js.fakeupdates criminal infrastructure on 2026-06-18, seizing 106 servers and domains and remediating 14,971 compromised websites. SocGholish, operated as a malware-as-a-service initial-access loader by TA569 and abused by Evil Corp, compromises legitimate WordPress sites to deliver fake-update lures that drop a JavaScript loader leading to NetSupport RAT, Cobalt Strike, and ransomware.
How International Law Enforcement Disrupts SocGholish works
On 2026-06-18 the Netherlands National High Tech Crime Unit (NHCTU/Politie NL), the Royal Canadian Mounted Police (RCMP), the U.S. FBI and Germany's BKA, supported by Europol and Eurojust, executed a joint action week against the SocGholish (also tracked as FakeUpdates, malware family js.fakeupdates) criminal infrastructure. The action took down 106 servers and domains worldwide, remediated 14,971 compromised websites, removed backdoors and malware from infected WordPress sites, and notified WordPress owners whose leaked login credentials had been identified — urging them to update their sites and rotate credentials. The disruption is part of the broader Operation Endgame coordinated takedown effort and targets one of the most prolific initial-access loaders in the criminal ecosystem.
SocGholish has been a constant threat since 2017. It is an initial-access broker / loader operated by the threat actor TA569 (also Mustard Tempest, DEV-0206, UNC1543) as a malware-as-a-service offering, selling access to downstream customers including the Russian cybercriminal group Evil Corp (DEV-0243, UNC2165, Manatee Tempest), LockBit, RansomHub, and Dridex/WastedLocker operators. The campaign compromises legitimate websites — frequently WordPress sites with weak or stolen wp-admin credentials — and injects JavaScript that serves fake browser-update lures (Google Chrome, Mozilla Firefox) to visitors via traffic-distribution systems such as Parrot TDS and Keitaro TDS (the latter operated by the affiliate TA2726).
Victims who click the fake update download a JavaScript stager (e.g. Update.js, LatestVersion.js) executed through Windows Script Host (wscript.exe). The loader fingerprints and filters victims — blocking WordPress admins, detecting webdriver/automated browsers, filtering mobile devices, and using an adViewEnabledKey localStorage flag and mouse-movement gating to evade analysis and prevent re-infection. Staging servers generate payloads dynamically at runtime and relay system-information and discovery output staged in TXT files under %AppData%\Local\Temp\. Hands-on-keyboard activity observed includes disabling RestrictedAdmin mode via the registry, PowerSharpPack UrbanBishop process injection for credential harvesting, and lateral movement over RDP and WMIC, with the typical final objective being ransomware deployment. Proxy-fronted C2 routes to backend infrastructure (including Tor), domains rotate every 2-3 days, and domain-shadowing on compromised registrar accounts is used to stand up disposable subdomains.
MITRE ATT&CK techniques used in TL-2026-0852
Credential Access
Collection
Lateral Movement
Defense Evasion
T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion
Privilege Escalation
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer
Initial Access
T1078 Valid Accounts; T1189 Drive-by Compromise; T1566 Phishing
Persistence
Discovery
T1082 System Information Discovery
defense-impairment
Impact
T1486 Data Encrypted for Impact
Resource Development
T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1608 Stage Capabilities
Affected products and versions in International Law Enforcement Disrupts SocGholish
- Automattic / WordPress community — WordPress
Vulnerable versions: sites with weak/stolen wp-admin credentials or outdated plugins
Fixed in: current WordPress core/plugins with rotated credentials and MFA - Microsoft — Windows (end-user endpoints)
Vulnerable versions: Windows endpoints running Windows Script Host
Fixed in: endpoints with WSH/script execution controls and EDR
Remediation for International Law Enforcement Disrupts SocGholish
Patches
- Update WordPress core, themes, and plugins to current versions
- Remove or patch vulnerable plugins used for initial compromise
Immediate actions
- Block the seized/known SocGholish inject and C2 domains and IPs at the perimeter and DNS resolver
- Audit WordPress sites for injected <script> tags, malicious .php proxies, and rogue admin accounts; remove backdoors
- Rotate all wp-admin and CMS credentials and check Politie NL / Have I Been Pwned notifications for leaked credentials
- Hunt for wscript.exe executing .js files from browser download paths and TXT staging under %AppData%\Local\Temp\
Workarounds
- Disable or restrict Windows Script Host where not required
- Restrict RestrictedAdmin-mode registry tampering via GPO and monitor LSA registry writes
Longer-term hardening
- Deploy EDR with behavioral detection for script-host execution and PowerShell/process-injection tradecraft
- Enforce MFA on all CMS/admin and remote-access (RDP) accounts
- Implement application control to block wscript/cscript execution of user-downloaded scripts
- Subscribe to TDS/inject feeds (Parrot TDS, Keitaro) and continuously monitor for fake-update lures
Timeline of International Law Enforcement Disrupts SocGholish
- SocGholish (FakeUpdates) first observed in the wild as a JavaScript-based fake-update loader; constant threat since.
- Parrot TDS, the primary traffic-distribution system feeding SocGholish injects, first publicly reported (Avast).
- ReliaQuest documents two SocGholish intrusions: Update.js via wscript.exe, RestrictedAdmin registry tampering, PowerSharpPack UrbanBishop injection, RDP/WMIC lateral movement, contained before ransomware.
- Operation Endgame launches as a coordinated international law-enforcement effort against malware delivery/loader infrastructure.
- SocGholish observed spread via ad tools and TA2726/Keitaro TDS, brokering access to LockBit, Evil Corp, and RansomHub.
- RomCom abuses SocGholish fake-update attacks to deliver a Mythic framework agent.
- Politie NL publicly announces the SocGholish infrastructure disruption and attributes use of the malware to Evil Corp.
- NHCTU, RCMP, FBI, BKA with Europol/Eurojust take down 106 servers and domains and remediate 14,971 websites; backdoors removed from infected WordPress sites and victims notified.
Sources cited for International Law Enforcement Disrupts SocGholish
- International law enforcement initiate hunt on malware group SocGholish (Politie NL)
- FAKEUPDATES (Malware Family) - Malpedia
- Unmasking SocGholish: Silent Push Untangles the Malware Web Behind the Pioneer of Fake Updates and Its Operator, TA569
- SocGholish: A Tale of FakeUpdates - ReliaQuest
- SocGholish Malware Spread via Ad Tools; Delivers Access to LockBit, Evil Corp, and Others - The Hacker News
- RomCom Uses SocGholish Fake Update Attacks to Deliver Mythic Agent Malware - The Hacker News
- SocGholish | Red Canary Threat Detection Report
- RansomHub Leverages SocGholish FakeUpdates to Target Government Sector - Halcyon
- SocGholish Malware: A Real Threat from a Fake Update - Proofpoint
- Operation Endgame
Threats related to International Law Enforcement Disrupts SocGholish
Detection coverage for TL-2026-0852
As of 2026-06-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0852 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.