An international law enforcement operation (Operation Endgame) seized 106 servers and numerous domains tied to SocGholish, a JavaScript malware framework used as an initial-access broker for ransomware groups including Evil Corp. The action also remediated nearly 15,000 compromised WordPress websites. SocGholish relies on traffic distribution systems (TDSs) to redirect users from legitimate sites to fake browser update pages, filtering out researchers and bots while targeting domain-joined enterprise systems for deeper intrusion. The FBI issued guidance urging organizations to change default JavaScript file associations, monitor endpoints for suspicious script execution, keep CMS platforms updated, and audit administrator accounts to defend against TDS-based attacks.