SocGholish malware downloader hijacking WordPress sites
Malware Activity
Summary
Hide ▲
Show ▼
SocGholish is a long-running JavaScript-based malware downloader also tracked as FakeUpdates that hijacks compromised WordPress sites to push fake browser update lures and deliver follow-on payloads. In June 2026, authorities from the Netherlands, Canada, Germany, and the U.S. carried out an Operation Endgame disruption that took 106 servers offline and cleaned 14,971 infected WordPress sites. The action reduced the network’s ability to spread malware and stage additional compromise through abused websites.
Related Happenings
Operation Endgame international cybercrime disruption initiative
Public Sector Action
H score57
First: 19.06.2026 18:07
Last: 19.06.2026 18:07
Sources 1
How related:
The takedown is part of Operation Endgame, an ongoing international law enforcement initiative to combat botnets and associated criminal infrastructures. It was launched in 2024.
About this happening:
Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
Operation Endgame international cybercrime disruption initiative
Public Sector ActionHow related: The takedown is part of Operation Endgame, an ongoing international law enforcement initiative to combat botnets and associated criminal infrastructures. It was launched in 2024.
About this happening: Operation Endgame is an ongoing international law enforcement initiative that now includes the takedown of SocGholish infrastructure, expanding disruption of botnets a...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware Activity
H score13
First: 18.06.2026 18:00
Last: 18.06.2026 18:00
Sources 1
About this happening:
A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware ActivityAbout this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Operation Endgame takedown of SocGholish and Evil Corp infrastructure
Law Enforcement
H score58
First: 18.06.2026 16:25
Last: 18.06.2026 16:25
Sources 1
How related:
Announced by the Dutch police on June 18, action was taken to remediate infections of 15,000 websites controlled by SocGholish group and to dismantle the botnet associated with the group.
About this happening:
International law enforcement disrupted SocGholish/FakeUpdates infrastructure in Operation Endgame on June 18, cleaning 14,971 compromised WordPress websites a...
Operation Endgame takedown of SocGholish and Evil Corp infrastructure
Law EnforcementHow related: Announced by the Dutch police on June 18, action was taken to remediate infections of 15,000 websites controlled by SocGholish group and to dismantle the botnet associated with the group.
About this happening: International law enforcement disrupted SocGholish/FakeUpdates infrastructure in Operation Endgame on June 18, cleaning 14,971 compromised WordPress websites a...
WordPress malware hides C2 data in Steam Community comments
Malware Activity
H score16
First: 01.06.2026 20:04
Last: 01.06.2026 20:04
Sources 1
About this happening:
A WordPress malware operation has been uncovered on approximately 1,980 websites, raising the risk of hidden command-and-control (C2) traffic and persistent page injec...
WordPress malware hides C2 data in Steam Community comments
Malware ActivityAbout this happening: A WordPress malware operation has been uncovered on approximately 1,980 websites, raising the risk of hidden command-and-control (C2) traffic and persistent page injec...
Compromised legitimate WordPress websites used to infect visitors with infostealer malware campaign expands across multiple victims
Campaign
H score34
First: 11.03.2026 16:45
Last: 11.03.2026 16:45
Sources 1
About this happening:
A global ClickFix campaign is abusing compromised WordPress sites to push infostealer malware to visitors, putting credentials and financial data at risk. The operatio...
Compromised legitimate WordPress websites used to infect visitors with infostealer malware campaign expands across multiple victims
CampaignAbout this happening: A global ClickFix campaign is abusing compromised WordPress sites to push infostealer malware to visitors, putting credentials and financial data at risk. The operatio...
Timeline
-
18.06.2026 16:25 4 articles · 27d ago
Law enforcement cleans 14,971 SocGholish-infected WordPress sites
Industry Or Public Sector UpdateAuthorities from the Netherlands, Canada, the United States, and Germany removed SocGholish malware from 14,971 compromised WordPress websites and took 106 servers and domains offline as part of Operation Endgame, a Europol- and Eurojust-supported effort targeting the infection chain linked to Evil Corp.
Show sources
- Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp — www.bleepingcomputer.com — 18.06.2026 16:25
- Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp — www.bleepingcomputer.com — 18.06.2026 16:25
- Operation Endgame Disrupts Malware Network Linked to Major Ransomware Gang — www.infosecurity-magazine.com — 19.06.2026 13:15
- Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites — thehackernews.com — 19.06.2026 18:07