Operation Endgame Dismantles SocGholish (FakeUpdates) Initial-Access Malware Network — 106 Servers and 101 Domains Seized (TA569 / Evil Corp)

Operation Endgame Dismantles SocGholish (FakeUpdates) (TL-2026-0863), also tracked as Operation Endgame, is a high-severity malware campaign, first published 2026-06-18. It is attributed to Mustard Tempest (Russia) with high confidence, affects WordPress / Automattic WordPress (self-hosted CMS sites), maps to 22 MITRE ATT&CK techniques (T1016, T1027, T1033), and is covered by 9 detection rules and 33 indicators of compromise.

Key facts for TL-2026-0863

Threat ID
TL-2026-0863
Also known as
Operation Endgame, SocGholish, FakeUpdates
Severity
HIGH
Status
MITIGATED
Category
MALWARE
First published
2026-06-18
Last reviewed
2026-06-18
Attribution
Mustard Tempest
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
government, financial, healthcare, education, manufacturing, technology, retail, professional services
Target regions
North America, Europe, Global
Detection rules
9
Indicators of compromise
33

Malware and tooling in Operation Endgame Dismantles SocGholish (FakeUpdates)

Malware and tooling: SocGholish - S1124, AsyncRAT - S1087, Cobalt Strike, NetSupport RAT, ParrotTDS / Keitaro TDS (TA2726)

On 18 June 2026, Operation Endgame disrupted the SocGholish (FakeUpdates) malware-as-a-service network operated by TA569/Mustard Tempest, an initial-access broker linked to Russia's Evil Corp. Law enforcement seized 106 servers and 101 domains and remediated roughly 14,971 compromised websites. Active since at least 2017, SocGholish injects JavaScript into hacked legitimate (largely WordPress) sites to serve fake browser-update lures that drop RATs (NetSupport, AsyncRAT), infostealers, Cobalt Strike beacons, and follow-on ransomware (WastedLocker, LockBit, RansomHub).

How Operation Endgame Dismantles SocGholish (FakeUpdates) works

SocGholish, also tracked as FakeUpdates, is a JavaScript-based loader and initial-access framework that has operated since at least 2017. It is run by the financially motivated actor Proofpoint tracks as TA569 (Microsoft: Mustard Tempest), an initial-access broker that sells footholds to Evil Corp affiliates and ransomware operators. Evil Corp is a Russian cybercriminal group previously responsible for the Zeus and Dridex banking trojans and large-scale ransomware and money-laundering operations.

The attack chain begins with compromised legitimate websites — disproportionately WordPress, which powers ~43% of the web. TA569 injects obfuscated JavaScript into these sites (often via domain shadowing on legitimate compromised domains, rotated every 2-3 days). Victim traffic is filtered through traffic distribution systems — TA569's actor-owned ParrotTDS and a malicious Keitaro TDS operated by TA2726 (the Apliteni-linked service) — to fingerprint and select targets. Selected visitors are shown a fake browser-update page. A click sends a postMessage to a hidden iframe that fetches a script (observed artifact: 'Google Launcher.js'), delivering a second-stage WSH JScript loader dubbed GhoLoader, which POSTs to its C2 via ActiveXObject(MSXML2.XMLHTTP) and performs host reconnaissance (process, software, domain-trust, system-information and network discovery).

From that foothold, SocGholish has dropped a range of second-stage payloads: NetSupport RAT (client32.exe), AsyncRAT, infostealers, and Cobalt Strike beacons — frequently culminating in hands-on-keyboard intrusion and ransomware deployment (WastedLocker, LockBit, RansomHub). The Center for Internet Security has repeatedly ranked SocGholish the top malware downloader, at times accounting for ~60% of observed downloader activity. A coordinated March 2026 wave (first seen 2026-03-02) deployed 11 stage-1 JavaScript injectors across 6 distinct C2 domains hosted across Panama, the United States, and Canada, linked by shared base64 campaign tokens.

On 18 June 2026, as part of Operation Endgame (launched 2024; the largest-ever international anti-cybercrime operation), the Netherlands NHTCU, Canada's RCMP, the U.S. FBI, and Germany's BKA — supported by Europol and Eurojust — seized 106 servers and 101 domains worldwide and remediated approximately 14,971 infected websites. Reporting also noted that login credentials for some 1.4 million WordPress sites had been found leaked and exposed to SocGholish-style compromise. This record documents the takedown and the historical TTPs and infrastructure for defender hunting and detection validation; it is not a vulnerability with a CVE.

MITRE ATT&CK techniques used in TL-2026-0863

Discovery

T1016 System Network Configuration Discovery; T1033 System Owner/User Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1482 Domain Trust Discovery; T1518 Software Discovery; T1614 System Location Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading

Execution

T1047 Windows Management Instrumentation; T1059 Command and Scripting Interpreter; T1204 User Execution

Exfiltration

T1048 Exfiltration Over Alternative Protocol

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer

Collection

T1074 Data Staged

Initial Access

T1189 Drive-by Compromise; T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1608 Stage Capabilities

Affected products and versions in Operation Endgame Dismantles SocGholish (FakeUpdates)

  • WordPress / Automattic — WordPress (self-hosted CMS sites)
    Vulnerable versions: compromised/outdated installations with stolen or weak admin credentials
    Fixed in: N/A — abuse of legitimate compromised sites, not a single CVE
  • Microsoft — Windows (end-user hosts running the fake-update JScript loader)
    Vulnerable versions: Windows hosts executing the SocGholish JScript loader via Windows Script Host
    Fixed in: N/A

Remediation for Operation Endgame Dismantles SocGholish (FakeUpdates)

Immediate actions

  • Block the seized/known SocGholish C2 and TDS domains and IPs at perimeter and DNS resolvers
  • Hunt endpoints for GhoLoader artifacts (WSH JScript executing MSXML2.XMLHTTP POSTs) and for 'Google Launcher.js' / fake-update download chains
  • Reset credentials and enforce MFA on all WordPress admin/CMS accounts; remove unauthorized admin accounts
  • Inspect compromised public web servers for injected/obfuscated JavaScript and unauthorized files; remove web injects

Workarounds

  • Disable Windows Script Host (WSH) where not required to break the JScript loader stage
  • Restrict execution of .js/.jse/.wsf/.hta via attack-surface-reduction rules or SRP/AppLocker

Longer-term hardening

  • Deploy EDR with behavioral detection for script-host execution (wscript/cscript/mshta) spawned from browsers and follow-on NetSupport/AsyncRAT/Cobalt Strike activity
  • Keep WordPress core, plugins, and themes patched; remove abandoned plugins and harden file-write permissions
  • Implement web-content integrity monitoring and a Content Security Policy to detect/limit injected scripts
  • User awareness: browsers never deliver updates via website pop-ups

Timeline of Operation Endgame Dismantles SocGholish (FakeUpdates)

  • SocGholish (FakeUpdates) first observed in the wild; operating as a JavaScript loader / initial-access framework since at least 2017 (MITRE ATT&CK S1124).
  • U.S. Treasury OFAC sanctions the Russia-based Evil Corp cybercrime group and the DOJ indicts leader Maksim Yakubets, formalizing the Evil Corp attribution later tied to SocGholish/TA569 operations.
  • Operation Endgame launched as the largest international law-enforcement operation against ransomware and cybercrime infrastructure.
  • UK National Crime Agency, with U.S. and Australian partners, sanctions additional Evil Corp members and publicly links Evil Corp to LockBit ransomware affiliation, reinforcing the actor nexus behind SocGholish initial-access activity.
  • Center for Internet Security ranks SocGholish the top malware downloader, at times accounting for roughly 60% of observed downloader activity.
  • Coordinated SocGholish wave deploys 11 stage-1 JavaScript injectors across 6 C2 domains (Panama, US, Canada) linked by shared base64 campaign tokens (Breakglass Intelligence).
  • Reporting notes login credentials for ~1.4 million WordPress sites found leaked and exposed to SocGholish-style compromise.
  • Authorities and vendors (Proofpoint, Orange Cyberdefense, CyberScoop) publicly tie SocGholish/TA569 to Russia's Evil Corp.
  • Operation Endgame seizes 106 servers and 101 domains worldwide and remediates ~14,971 infected websites, disrupting the TA569/SocGholish network.

Sources cited for Operation Endgame Dismantles SocGholish (FakeUpdates)

Threats related to Operation Endgame Dismantles SocGholish (FakeUpdates)

Detection coverage for TL-2026-0863

As of 2026-06-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0863 across Splunk SPL, Microsoft KQL and Sigma, covering 33 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats