Skip to content

FAKEUPDATES

Also known as: FakeUpdate, GhoLoader, SocGholish

FAKEUPDATES is a downloader written in JavaScript that communicates via HTTP. Supported payload types include executables and JavaScript. It writes the payloads to disk prior to launching them. FAKEUPDATES has led to further compromise via additional malware families that include CHTHONIC, DRIDEX, EMPIRE, KOADIC, DOPPELPAYMER, and AZORULT.

FAKEUPDATES has been heavily used by UNC1543, a financially motivated group.

Linked Threat Actors

GOLD PRELUDE

C2 Infrastructure

Hosting/VPS100%

Last 7 days

Apr 18, 2026
C2 Hosts: 1
Apr 17, 2026
C2 Hosts: 1
Apr 15, 2026
C2 Hosts: 1
Apr 14, 2026
C2 Hosts: 1

Further Reading