International Law Enforcement Disrupts SocGholish (js.fakeupdates) Access-Broker Infrastructure Linked to Evil Corp

International Law Enforcement Disrupts SocGholish (TL-2026-0852), also tracked as FakeUpdates, is a high-severity malware campaign, first published 2026-06-18. It is attributed to Mustard Tempest (Russia) with high confidence, affects Automattic / WordPress community WordPress, maps to 21 MITRE ATT&CK techniques (T1003, T1005, T1021), and is covered by 9 detection rules and 38 indicators of compromise.

Key facts for TL-2026-0852

Threat ID
TL-2026-0852
Also known as
FakeUpdates, js.fakeupdates, SocGholish takedown, Operation Endgame (SocGholish action week)
Severity
HIGH
Status
TRACKING
Category
MALWARE
First published
2026-06-18
Last reviewed
2026-06-18
Attribution
Mustard Tempest
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
government, critical infrastructure, financial, healthcare, media, manufacturing, transportation
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
38

Malware and tooling in International Law Enforcement Disrupts SocGholish

Malware and tooling: Raspberry Robin, js.fakeupdates, Cobalt Strike, Keitaro TDS, NetSupport RAT, Parrot TDS, PowerSharpPack UrbanBishop

An international law-enforcement coalition (Netherlands NHCTU, Canada RCMP, US FBI, Germany BKA, with Europol and Eurojust) disrupted the SocGholish / js.fakeupdates criminal infrastructure on 2026-06-18, seizing 106 servers and domains and remediating 14,971 compromised websites. SocGholish, operated as a malware-as-a-service initial-access loader by TA569 and abused by Evil Corp, compromises legitimate WordPress sites to deliver fake-update lures that drop a JavaScript loader leading to NetSupport RAT, Cobalt Strike, and ransomware.

How International Law Enforcement Disrupts SocGholish works

On 2026-06-18 the Netherlands National High Tech Crime Unit (NHCTU/Politie NL), the Royal Canadian Mounted Police (RCMP), the U.S. FBI and Germany's BKA, supported by Europol and Eurojust, executed a joint action week against the SocGholish (also tracked as FakeUpdates, malware family js.fakeupdates) criminal infrastructure. The action took down 106 servers and domains worldwide, remediated 14,971 compromised websites, removed backdoors and malware from infected WordPress sites, and notified WordPress owners whose leaked login credentials had been identified — urging them to update their sites and rotate credentials. The disruption is part of the broader Operation Endgame coordinated takedown effort and targets one of the most prolific initial-access loaders in the criminal ecosystem.

SocGholish has been a constant threat since 2017. It is an initial-access broker / loader operated by the threat actor TA569 (also Mustard Tempest, DEV-0206, UNC1543) as a malware-as-a-service offering, selling access to downstream customers including the Russian cybercriminal group Evil Corp (DEV-0243, UNC2165, Manatee Tempest), LockBit, RansomHub, and Dridex/WastedLocker operators. The campaign compromises legitimate websites — frequently WordPress sites with weak or stolen wp-admin credentials — and injects JavaScript that serves fake browser-update lures (Google Chrome, Mozilla Firefox) to visitors via traffic-distribution systems such as Parrot TDS and Keitaro TDS (the latter operated by the affiliate TA2726).

Victims who click the fake update download a JavaScript stager (e.g. Update.js, LatestVersion.js) executed through Windows Script Host (wscript.exe). The loader fingerprints and filters victims — blocking WordPress admins, detecting webdriver/automated browsers, filtering mobile devices, and using an adViewEnabledKey localStorage flag and mouse-movement gating to evade analysis and prevent re-infection. Staging servers generate payloads dynamically at runtime and relay system-information and discovery output staged in TXT files under %AppData%\Local\Temp\. Hands-on-keyboard activity observed includes disabling RestrictedAdmin mode via the registry, PowerSharpPack UrbanBishop process injection for credential harvesting, and lateral movement over RDP and WMIC, with the typical final objective being ransomware deployment. Proxy-fronted C2 routes to backend infrastructure (including Tor), domains rotate every 2-3 days, and domain-shadowing on compromised registrar accounts is used to stand up disposable subdomains.

MITRE ATT&CK techniques used in TL-2026-0852

Credential Access

T1003 OS Credential Dumping

Collection

T1005 Data from Local System

Lateral Movement

T1021 Remote Services

Defense Evasion

T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion

Privilege Escalation

T1055 Process Injection

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1105 Ingress Tool Transfer

Initial Access

T1078 Valid Accounts; T1189 Drive-by Compromise; T1566 Phishing

Persistence

T1078 Valid Accounts

Discovery

T1082 System Information Discovery

defense-impairment

T1112 Modify Registry

Impact

T1486 Data Encrypted for Impact

Resource Development

T1583 Acquire Infrastructure; T1586 Compromise Accounts; T1608 Stage Capabilities

Affected products and versions in International Law Enforcement Disrupts SocGholish

  • Automattic / WordPress community — WordPress
    Vulnerable versions: sites with weak/stolen wp-admin credentials or outdated plugins
    Fixed in: current WordPress core/plugins with rotated credentials and MFA
  • Microsoft — Windows (end-user endpoints)
    Vulnerable versions: Windows endpoints running Windows Script Host
    Fixed in: endpoints with WSH/script execution controls and EDR

Remediation for International Law Enforcement Disrupts SocGholish

Patches

  • Update WordPress core, themes, and plugins to current versions
  • Remove or patch vulnerable plugins used for initial compromise

Immediate actions

  • Block the seized/known SocGholish inject and C2 domains and IPs at the perimeter and DNS resolver
  • Audit WordPress sites for injected <script> tags, malicious .php proxies, and rogue admin accounts; remove backdoors
  • Rotate all wp-admin and CMS credentials and check Politie NL / Have I Been Pwned notifications for leaked credentials
  • Hunt for wscript.exe executing .js files from browser download paths and TXT staging under %AppData%\Local\Temp\

Workarounds

  • Disable or restrict Windows Script Host where not required
  • Restrict RestrictedAdmin-mode registry tampering via GPO and monitor LSA registry writes

Longer-term hardening

  • Deploy EDR with behavioral detection for script-host execution and PowerShell/process-injection tradecraft
  • Enforce MFA on all CMS/admin and remote-access (RDP) accounts
  • Implement application control to block wscript/cscript execution of user-downloaded scripts
  • Subscribe to TDS/inject feeds (Parrot TDS, Keitaro) and continuously monitor for fake-update lures

Timeline of International Law Enforcement Disrupts SocGholish

  • SocGholish (FakeUpdates) first observed in the wild as a JavaScript-based fake-update loader; constant threat since.
  • Parrot TDS, the primary traffic-distribution system feeding SocGholish injects, first publicly reported (Avast).
  • ReliaQuest documents two SocGholish intrusions: Update.js via wscript.exe, RestrictedAdmin registry tampering, PowerSharpPack UrbanBishop injection, RDP/WMIC lateral movement, contained before ransomware.
  • Operation Endgame launches as a coordinated international law-enforcement effort against malware delivery/loader infrastructure.
  • SocGholish observed spread via ad tools and TA2726/Keitaro TDS, brokering access to LockBit, Evil Corp, and RansomHub.
  • RomCom abuses SocGholish fake-update attacks to deliver a Mythic framework agent.
  • Politie NL publicly announces the SocGholish infrastructure disruption and attributes use of the malware to Evil Corp.
  • NHCTU, RCMP, FBI, BKA with Europol/Eurojust take down 106 servers and domains and remediate 14,971 websites; backdoors removed from infected WordPress sites and victims notified.

Sources cited for International Law Enforcement Disrupts SocGholish

Threats related to International Law Enforcement Disrupts SocGholish

Detection coverage for TL-2026-0852

As of 2026-06-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0852 across Splunk SPL, Microsoft KQL and Sigma, covering 38 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats