Skip to content

SocGholish

SocGholish, also known as FakeUpdates, is a Windows-focused JavaScript malware delivery framework and initial-access service active since at least 2017–2018.

Profile source: Mallory opens in a new tab

SocGholish

Family profile

SocGholish, also known as FakeUpdates, is a Windows-focused JavaScript malware delivery framework and initial-access service active since at least 2017–2018. It compromises legitimate websites, including WordPress sites accessed using stolen administrator credentials, and injects scripts that selectively redirect visitors to fraudulent browser or software-update pages. Victims are socially engineered to download and execute archives, JavaScript, or HTA content masquerading as updates. The loader profiles hosts, collects system and security-product information, performs anti-analysis checks, and uses Windows command interpreters or PowerShell to retrieve and launch follow-on payloads. SocGholish has delivered Cobalt Strike, NetSupport RAT, Dridex, banking malware, information stealers, and ransomware-enabling tooling, and has been used as a precursor to targeted ransomware incidents involving WastedLocker and LockBit. It is widely associated with the Indrik Spider/Evil Corp cybercriminal ecosystem, although delivery and access-broker partnerships can involve other actors. Campaigns use compromised websites, drive-by downloads, watering-hole activity, malicious advertising, and occasionally spam links to compromised sites; targeting commonly prioritizes first-time Windows visitors arriving through search engines or other third-party referrers.

Capabilities

  • Defense Evasion
  • Initial Access
  • Reconnaissance

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 29, 2026
Last activity
Sep 5, 2026
Feed role
C2 / Distribution
Host form
0 IP / 449 hostnames

Leading locations

  • US211
  • DE36
  • FR33
  • IT27
  • ES14
  • GB12
  • BR11
  • ZA11
  • AU9
  • VN9
  • DK8
  • PL7

Leading providers

  • Cloudflare London, LLC32
  • Oracle Corporation31
  • OVH SAS26
  • Cloudflare, Inc.23
  • IONOS SE22
  • Aruba S.p.A.18

Infrastructure traits

  • Hosting 432
  • Anycast 85
  • Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

17 named in public reporting
Shady Squirrel

Shady Squirrel ... sends traffic to initial access brokers and cybercriminals like SocGholish ... SocGholish is believed to have regained access to thousands of compromised sites by teaming up with the threat actor merely days after its infrastructure was disrupted in a law enforcement operation.

INDRIK SPIDER

SocGholish is an advanced delivery framework used in drive-by-download and watering hole attacks... First seen in the wild in April 2018, SocGholish is a drive-by-download framework used in social engineering attacks to deliver a range of remote access trojans and ransom tools.

SilverFish

This NDSW/NDSX malware — also referred to as FakeUpdates or SocGholish by other research groups — is responsible for redirecting site visitors to malicious pages designed to trick victims into loading and installing fake browser updates.

Mustard Tempest

The tech giant said it observed the FakeUpdates (aka SocGholish) malware being delivered via existing Raspberry Robin infections on July 26, 2022.

KongTuke

Recorded Future exploits TDS to demonstrate a high-level activity strategy that includes regularly updating URLs embedded in WordPress sites, adding additional servers, and improving TDS logic to evade detection, and has been linked to SocGholish and D3F@ck Loader malware, as well as the Rhysida and Interlock ransomware groups.

RomCom

Active since 2017 and also known as FakeUpdates, SocGholish is a JavaScript (JS)-based downloader malware that typically serves as a conduit for next-stage malware from various threat actors like Evil Corp, LockBit, RansomHub, Dridex, and Raspberry Robin.

TA2726

Active since 2017 and also known as FakeUpdates, SocGholish is a JavaScript (JS)-based downloader malware that typically serves as a conduit for next-stage malware from various threat actors like Evil Corp, LockBit, RansomHub, Dridex, and Raspberry Robin.

TA866

TAG-124 has also been associated with SocGholish and D3F@ck loader malware, which provide remote access and malware delivery for financially motivated activity.

TA0569

A coordinated SocGholish (FakeUpdates) campaign wave launched 2026-03-02 deployed 11 stage-1 JavaScript injectors across 6 distinct C2 domains hosted by 4 providers spanning Panama, the United States, and Canada.

UNC2726

A coordinated SocGholish (FakeUpdates) campaign wave launched 2026-03-02 deployed 11 stage-1 JavaScript injectors across 6 distinct C2 domains hosted by 4 providers spanning Panama, the United States, and Canada.

Purple Vallhund

"SocGholish, also called FakeUpdates, is a JavaScript loader malware that's distributed via compromised websites by masquerading as deceptive updates for web browsers like Google Chrome or Mozilla Firefox..."

LockBit

SocGholish, operated by TA569, actually functions as a Malware-as-a-Service (MaaS) vendor, selling access to compromised systems to various financially motivated cybercriminal clients. The primary tactic used involves deceptive “fake browser update” lures...

Unit 29155

SocGholish, operated by TA569, actually functions as a Malware-as-a-Service (MaaS) vendor, selling access to compromised systems to various financially motivated cybercriminal clients. The primary tactic used involves deceptive “fake browser update” lures...

UNC4108

SocGholish, operated by TA569, actually functions as a Malware-as-a-Service (MaaS) vendor, selling access to compromised systems to various financially motivated cybercriminal clients. The primary tactic used involves deceptive “fake browser update” lures...

Scarlet Goldfinch

"Throughout 2024 we continued to observe a low volume of SocGholish infections... upon execution the JavaScript payload connects back to SocGholish infrastructure... and can retrieve additional malware."

VexTrio Viper

“VexTrio Viper runs the largest and oldest known TDS with over 165 affiliates including SocGholish and ClearFake.”

GRU Unit 29155

Arctic Wolf Labs assesses with a medium-to-high confidence level that Russia’s GRU unit 29155 is utilizing SocGholish to target victims. .. Actor: TA569 is considered the primary threat actor deploying and maintaining SocGholish... The operator serves as an Initial Access Broker (IAB), selling access to compromised systems to ransomware affiliates.

Exploited software

Vulnerabilities linked to SocGholish

3 CVEs

MITRE ATT&CK

SocGholish in ATT&CK

79 distinct techniques

Techniques

79 techniques
T1078.004 Cloud Accounts T1189 Drive-by Compromise T1036 Masquerading T1057 Process Discovery T1482 Domain Trust Discovery T1018 Remote System Discovery T1007 System Service Discovery T1059 Command and Scripting Interpreter T1566.002 Spearphishing Link T1204 User Execution T1069.002 Domain Groups T1087 Account Discovery T1016 System Network Configuration Discovery T1105 Ingress Tool Transfer T1033 System Owner/User Discovery T1071 Application Layer Protocol T1608.004 Drive-by Target T1584.001 Domains T1102 Web Service T1205 Traffic Signaling T1584 Compromise Infrastructure T1082 System Information Discovery T1497 Virtualization/Sandbox Evasion T1059.007 JavaScript T1027 Obfuscated Files or Information T1059.005 Visual Basic T1059.001 PowerShell T1059.003 Windows Command Shell T1555 Credentials from Password Stores T1204.002 Malicious File T1566 Phishing T1497.001 System Checks T1620 Reflective Code Loading T1071.001 Web Protocols T1518 Software Discovery T1210 Exploitation of Remote Services T1055 Process Injection T1005 Data from Local System T1552.001 Credentials In Files T1048 Exfiltration Over Alternative Protocol T1539 Steal Web Session Cookie T1047 Windows Management Instrumentation T1204.001 Malicious Link T1615 Group Policy Discovery T1558 Steal or Forge Kerberos Tickets T1218.011 Rundll32 T1036.005 Match Legitimate Resource Name or Location T1583 Acquire Infrastructure T1036.004 Masquerade Task or Service T1555.003 Credentials from Web Browsers T1090.003 Multi-hop Proxy T1583.001 Domains T1078 Valid Accounts T1537 Transfer Data to Cloud Account T1587.001 Malware T1584.006 Web Services T1110.003 Password Spraying T1219 Remote Access Tools T1190 Exploit Public-Facing Application T1505.003 Web Shell T1136 Create Account T1056 Input Capture T1046 Network Service Discovery T1547.001 Registry Run Keys / Startup Folder T1074 Data Staged T1590 Gather Victim Network Information T1056.001 Keylogging T1556 Modify Authentication Process T1608.001 Upload Malware T1486 Data Encrypted for Impact T1187 Forced Authentication T1614.001 System Language Discovery T1041 Exfiltration Over C2 Channel T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol T1027.013 Encrypted/Encoded File T1074.001 Local Data Staging T1027.015 Compression T1614 System Location Discovery T1583.006 Web Services

Reporting

Research mentioning SocGholish

Aug 11
Lazarusholic Bluesky

Post by @lazarusholic.bsky.social - Bluesky

A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.

Aug 3
Malware News

Cyber Conflict Briefing Q2 2026 - Malware Analysis - Malware Analysis, News and Indicators

The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.

Aug 3
Cyberveille

Tendances ransomware - Semaine 31/2026 | CyberVeille

Aug 3
Hookphish

Ransomware Group qilin Hits: Service Electric

Aug 3
Hookphish

Ransomware Group qilin Hits: Freedom Claims Management

Aug 2
Hookphish

Ransomware Group shinyhunters Hits: Questel SAS

Aug 2
Hookphish

Ransomware Group qilin Hits: Wire Products

Aug 1
Cyberveille

Vague d'exploitation VPN : Palo Alto, Fortinet, Citrix et Check Point ciblés par des ransomwares | CyberVeille

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.