Operation Endgame takedown of SocGholish and Evil Corp infrastructure
Law Enforcement
Summary
Hide ▲
Show ▼
International law enforcement disrupted SocGholish/FakeUpdates infrastructure in Operation Endgame on June 18, cleaning 14,971 compromised WordPress websites and taking down 106 servers and domains. The action targeted malware distribution infrastructure used to push follow-on payloads and was linked to activity involving Evil Corp. Authorities from the Netherlands, Canada, the United States, and Germany participated, with support from Europol and Eurojust. Dutch police notified affected site owners to change credentials, enable multi-factor authentication, delete unknown WordPress accounts, and keep sites updated.
Related Happenings
Operation Endgame international cybercrime disruption initiative
Public Sector Action
H score57
First: 19.06.2026 18:07
Last: 19.06.2026 18:07
Sources 1
How related:
The takedown is part of Operation Endgame, an ongoing international law enforcement initiative to combat botnets and associated criminal infrastructures. It was launched in 2024.
About this happening:
Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
Operation Endgame international cybercrime disruption initiative
Public Sector ActionHow related: The takedown is part of Operation Endgame, an ongoing international law enforcement initiative to combat botnets and associated criminal infrastructures. It was launched in 2024.
About this happening: Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
SocGholish malware downloader hijacking WordPress sites
Malware Activity
H score57
First: 18.06.2026 16:25
Last: 18.06.2026 16:25
Sources 1
How related:
Active since 2017 and also known as FakeUpdates, SocGholish is a JavaScript (JS)-based downloader malware that typically serves as a conduit for next-stage malware from various threat actors like Evil Corp (aka DEV-0243, Indrik Spider, and UNC2165), LockBit, RansomHub, Dridex, and Raspberry Robin (aka Roshtyak).
About this happening:
SocGholish is a long-running JavaScript-based malware downloader also tracked as FakeUpdates that hijacks compromised WordPress sites to push fake browser update...
SocGholish malware downloader hijacking WordPress sites
Malware ActivityHow related: Active since 2017 and also known as FakeUpdates, SocGholish is a JavaScript (JS)-based downloader malware that typically serves as a conduit for next-stage malware from various threat actors like Evil Corp (aka DEV-0243, Indrik Spider, and UNC2165), LockBit, RansomHub, Dridex, and Raspberry Robin (aka Roshtyak).
About this happening: SocGholish is a long-running JavaScript-based malware downloader also tracked as FakeUpdates that hijacks compromised WordPress sites to push fake browser update...
FBI takedown of Outsider Enterprise phishing service
Law Enforcement
H score63
First: 14.06.2026 17:36
Last: 14.06.2026 17:36
Sources 1
About this happening:
The FBI and partners dismantled Outsider Enterprise, a phishing-as-a-service operation tied to thousands of phishing websites and large-scale credential theft....
FBI takedown of Outsider Enterprise phishing service
Law EnforcementAbout this happening: The FBI and partners dismantled Outsider Enterprise, a phishing-as-a-service operation tied to thousands of phishing websites and large-scale credential theft....
AudiA6 laundering ecosystem and Dark2Web forum
Threat Actor Meta
H score31
First: 11.06.2026 18:55
Last: 11.06.2026 18:55
Sources 1
About this happening:
AudiA6 was disrupted as an industrial-scale cryptocurrency laundering service used by ransomware gangs and other cybercriminal networks. Europol said the ecosystem lau...
AudiA6 laundering ecosystem and Dark2Web forum
Threat Actor MetaAbout this happening: AudiA6 was disrupted as an industrial-scale cryptocurrency laundering service used by ransomware gangs and other cybercriminal networks. Europol said the ecosystem lau...
Europol-led AudiA6 crypto-laundering takedown
Law Enforcement
H score29
First: 11.06.2026 18:55
Last: 11.06.2026 18:55
Sources 1
About this happening:
Law enforcement dismantled AudiA6, a cryptocurrency laundering service used by ransomware gangs and other cybercriminal networks, in a June 10, 2026 multinatio...
Europol-led AudiA6 crypto-laundering takedown
Law EnforcementAbout this happening: Law enforcement dismantled AudiA6, a cryptocurrency laundering service used by ransomware gangs and other cybercriminal networks, in a June 10, 2026 multinatio...
Timeline
-
18.06.2026 16:25 4 articles · 27d ago
International law enforcement takes down SocGholish infrastructure linked to Evil Corp
Legal Policy Action UpdateInternational law enforcement agencies cleaned 14,971 compromised WordPress websites and took 106 servers and domains offline in Operation Endgame, disrupting a SocGholish infection chain linked to Evil Corp. Authorities from the Netherlands (NHCTU), Canada (RCMP), the United States (FBI), and Germany (BKA) carried out the action, and Dutch police told website owners to change credentials, enable multi-factor authentication, delete unknown WordPress accounts, and keep WordPress up to date.
Show sources
- Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp — www.bleepingcomputer.com — 18.06.2026 16:25
- Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp — www.bleepingcomputer.com — 18.06.2026 16:25
- Operation Endgame Disrupts Malware Network Linked to Major Ransomware Gang — www.infosecurity-magazine.com — 19.06.2026 13:15
- Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites — thehackernews.com — 19.06.2026 18:07