International law enforcement agencies from the Netherlands, Canada, the US, and Germany cleaned SocGholish malware from nearly 15,000 compromised WordPress websites and took down 106 servers and domains as part of Operation Endgame. The action targeted infrastructure linked to Evil Corp, a Russian cybercrime group active since 2007. SocGholish (also known as FakeUpdates) is a JavaScript-based malware downloader that hijacks websites to trick visitors into installing fake browser updates, and has been used to deploy ransomware families including WastedLocker, Hades, and Macaw Locker. Dutch police also removed backdoors and advised site owners to rotate credentials, enable MFA, and audit WordPress accounts.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:
215 Impressions