Operation Endgame Shuts Down SocGholish Infrastructure and Cleans Nearly 15,000 WordPress Sites
Law enforcement agencies from the Netherlands, Canada, Germany and the United States have jointly dismantled parts of the malicious backend used by the SocGholish campaign and removed infections from 14,971 WordPress installations.
Officials said the coordinated measures cut cybercriminals off from compromised systems. Maikel Rollman of the Netherlands National High Tech Crime Unit explained that removing access to infected hosts reduces harm to citizens, businesses and organizations worldwide, slows the spread of malware and lowers the chance those systems are reused to attack critical services. He added this takedown is the first in a series of planned actions against SocGholish.
The disruption forms part of Operation Endgame, an international law enforcement program launched in 2024 to target botnets and the criminal infrastructures that support them. As part of the operation authorities seized or disabled 106 servers tied to SocGholish and remediated nearly 15,000 compromised WordPress sites. Site operators have been contacted and advised to update their content management systems, reset credentials and remove any unfamiliar accounts.
SocGholish, also known as FakeUpdates, has been active since 2017. It is a JavaScript-based downloader that serves as a first-stage delivery mechanism for many follow-on threats from actors such as Evil Corp (also tracked as DEV-0243, Indrik Spider, and UNC2165), LockBit, RansomHub, Dridex and Raspberry Robin (sometimes called Roshtyak). The malware is commonly delivered through hijacked websites that masquerade as fake browser or software update prompts for programs like Google Chrome and Mozilla Firefox. Researchers have linked the operators to multiple tracked aliases, including Gold Prelude, Mustard Tempest, Purple Vallhund, TA569 and UNC1543.
Technical analysis last year by Silent Push showed that SocGholish infections typically stem from already-compromised websites and can be introduced in several ways. Injections sometimes place the malicious JavaScript directly into pages, while other variants employ an intermediary JS file that pulls in the payload for the actual injection.
In a notable development in November 2025, Arctic Wolf reported that the RomCom threat cluster leveraged SocGholish to deliver the Mythic Agent implant, illustrating how initial-access services tied to SocGholish are used by a wide range of operators with differing goals.
Threat intelligence firms have documented the multi-layered nature of SocGholish’s delivery chain. Orange Cyberdefense observed infections that dropped other JavaScript loaders such as Gholoader and MintsLoader, which in turn install additional payloads like GhostWeaver, LockBit, AsyncRAT and NetSupport RAT. The company noted the framework relies on stacked delivery stages and works with traffic distribution systems (TDS) run by affiliates such as TA2726.
The Shadowserver Foundation reported that many of the compromised WordPress sites were altered to host parts of the attackers’ infrastructure. The majority of these hacked sites were located in the United States, followed by Germany, France, India, Brazil, Singapore, Italy, Indonesia, Canada and Vietnam. Shadowserver also highlighted the frequent use of domain shadowing: intruders who gain control of an authoritative DNS or registrar account quietly create subdomains under a legitimate domain and point them to malicious external servers, leveraging the parent domain’s reputation to avoid detection.
Compromised websites are often leveraged by multiple criminal groups, exposing visitors to an array of threats. Which malicious payload a visitor encounters can depend on variables such as their geographic location, browser fingerprint and operating system. Proofpoint characterized TA569 as an opportunistic actor that indiscriminately compromises sites, noting higher-traffic domains yield more victims and that the actor has targeted organizations across many sectors - from nonprofits and schools to healthcare, legal and real estate.
Infoblox described SocGholish as a staged JavaScript framework that converts infected sites into drive-by download platforms through four primary phases: acquiring traffic, filtering that traffic, presenting payload lures and executing implants on target devices. Infoblox added that TA569 both composes a large number of compromised pages themselves and accepts redirected traffic from affiliates; those affiliates fingerprint visitors and pass suitable targets to SocGholish in return for payment. Known affiliates and traffic sellers tied to the ecosystem over time include TA2726, Parrot TDS and JunkyTDS, while operators have also relied on commercial filtering platforms such as Keitaro and zTDS to decide whether to forward a user to the malicious chain or send them to benign content.
Recent telemetry from Infoblox indicated roughly 55% of its cloud customers attempted to connect to SocGholish infrastructure this year, and the attacks have targeted nearly every industry sector in the last five months. Among the most impacted verticals were government, education, banking, healthcare, non-IT services, financial services, IT consulting, utilities, insurance and transportation - underscoring that SocGholish is a broad, cross-industry threat rather than a niche campaign.