Skip to content
Malware family Windows

SocGholish

SocGholish, also known as FakeUpdates, is a Windows-focused malware loader and initial-access platform distributed through compromised legitimate websites, especially hacked WordPress sites, using fake browser or software update lures.

Profile source: Mallory opens in a new tab

SocGholish

Family profile

SocGholish, also known as FakeUpdates, is a Windows-focused malware loader and initial-access platform distributed through compromised legitimate websites, especially hacked WordPress sites, using fake browser or software update lures. It is widely tracked as a major initial-access mechanism in the cybercrime ecosystem and has been associated with the financially motivated threat cluster TA569 and linked in public reporting to Evil Corp. The operation has also been referred to in some contexts alongside GhoLoader as part of its downstream execution chain.

The malware is typically delivered when visitors to compromised sites are selectively profiled and redirected through traffic-distribution logic before being shown fraudulent update prompts. Eligible victims who execute the downloaded JavaScript-based payload initiate a loader sequence that can fetch and run additional code on Windows systems. SocGholish is used to gain unauthorized access to victim environments and to enable follow-on criminal activity, including deployment of additional malware and resale of access to other actors, most notably ransomware operators.

Operational reporting describes SocGholish as part of a broader malware-as-a-service or cybercrime-as-a-service ecosystem in which compromised websites, traffic filtering, staged payload delivery, and downstream monetization are separated across different actors. Its infrastructure and distribution network have been the subject of major international disruption efforts under Operation Endgame, including remediation of large numbers of compromised websites and seizure of supporting infrastructure. Despite such disruptions, SocGholish has remained notable for its scale, persistence, and role in feeding later-stage intrusions.

Capabilities

  • Defense Evasion
  • Initial Access
  • Post Exploitation

Observed infrastructure

Last seven days

First activity
Jul 21, 2026
Last activity
Jul 22, 2026
Feed role
Distribution
Host form
0 IP / 940 hostnames

Leading locations

  • US471
  • DE77
  • FR61
  • IT56
  • ES28
  • DK25
  • PL22
  • GB17
  • ZA17
  • NL16
  • BR14
  • VN13

Leading providers

  • Oracle Corporation84
  • Cloudflare, Inc.63
  • IONOS SE58
  • Cloudflare London, LLC50
  • OVH SAS42
  • Namecheap, Inc.38

Infrastructure traits

  • Hosting 899
  • Anycast 165
  • Proxy 50
  • Vpn 5
  • Mobile 2

Reported operators

Threat actors

15 named in public reporting
Indrik Spider

selected Windows users are handed to TA569's SocGholish fake browser update. The lure downloads Google Launcher.js

KongTuke

Recorded Future exploits TDS to demonstrate a high-level activity strategy that includes regularly updating URLs embedded in WordPress sites, adding additional servers, and improving TDS logic to evade detection, and has been linked to SocGholish and D3F@ck Loader malware, as well as the Rhysida and Interlock ransomware groups.

RomCom

Active since 2017 and also known as FakeUpdates, SocGholish is a JavaScript (JS)-based downloader malware that typically serves as a conduit for next-stage malware from various threat actors like Evil Corp, LockBit, RansomHub, Dridex, and Raspberry Robin.

TA2726

Active since 2017 and also known as FakeUpdates, SocGholish is a JavaScript (JS)-based downloader malware that typically serves as a conduit for next-stage malware from various threat actors like Evil Corp, LockBit, RansomHub, Dridex, and Raspberry Robin.

SocGholish

The threat actors SocGholish ... compromise legitimate WordPress sites and use Traffic Direction/Distribution Systems (TDS) to redirect visitors to webinjects hosted there ... and trick end users into drive by downloading of malware.

TA866

TAG-124 has also been associated with SocGholish and D3F@ck loader malware, which provide remote access and malware delivery for financially motivated activity.

TA0569

A coordinated SocGholish (FakeUpdates) campaign wave launched 2026-03-02 deployed 11 stage-1 JavaScript injectors across 6 distinct C2 domains hosted by 4 providers spanning Panama, the United States, and Canada.

UNC2726

A coordinated SocGholish (FakeUpdates) campaign wave launched 2026-03-02 deployed 11 stage-1 JavaScript injectors across 6 distinct C2 domains hosted by 4 providers spanning Panama, the United States, and Canada.

Purple Vallhund

"SocGholish, also called FakeUpdates, is a JavaScript loader malware that's distributed via compromised websites by masquerading as deceptive updates for web browsers like Google Chrome or Mozilla Firefox..."

LockBit

SocGholish, operated by TA569, actually functions as a Malware-as-a-Service (MaaS) vendor, selling access to compromised systems to various financially motivated cybercriminal clients. The primary tactic used involves deceptive “fake browser update” lures...

Unit 29155

SocGholish, operated by TA569, actually functions as a Malware-as-a-Service (MaaS) vendor, selling access to compromised systems to various financially motivated cybercriminal clients. The primary tactic used involves deceptive “fake browser update” lures...

UNC4108

SocGholish, operated by TA569, actually functions as a Malware-as-a-Service (MaaS) vendor, selling access to compromised systems to various financially motivated cybercriminal clients. The primary tactic used involves deceptive “fake browser update” lures...

Scarlet Goldfinch

"Throughout 2024 we continued to observe a low volume of SocGholish infections... upon execution the JavaScript payload connects back to SocGholish infrastructure... and can retrieve additional malware."

VexTrio Viper

“VexTrio Viper runs the largest and oldest known TDS with over 165 affiliates including SocGholish and ClearFake.”

GRU Unit 29155

Arctic Wolf Labs assesses with a medium-to-high confidence level that Russia’s GRU unit 29155 is utilizing SocGholish to target victims. .. Actor: TA569 is considered the primary threat actor deploying and maintaining SocGholish... The operator serves as an Initial Access Broker (IAB), selling access to compromised systems to ransomware affiliates.

Exploited software

Vulnerabilities linked to SocGholish

1 CVEs

MITRE ATT&CK

SocGholish in ATT&CK

58 distinct techniques

Techniques

58 techniques
T1204 User Execution T1105 Ingress Tool Transfer T1497 Virtualization/Sandbox Evasion T1497.001 System Checks T1566.002 Spearphishing Link T1036 Masquerading T1059.007 JavaScript T1189 Drive-by Compromise T1082 System Information Discovery T1078 Valid Accounts T1204.002 Malicious File T1587.001 Malware T1584.006 Web Services T1566 Phishing T1071 Application Layer Protocol T1584 Compromise Infrastructure T1110.003 Password Spraying T1059.001 PowerShell T1219 Remote Access Tools T1190 Exploit Public-Facing Application T1583.001 Domains T1205 Traffic Signaling T1584.001 Domains T1505.003 Web Shell T1136 Create Account T1027 Obfuscated Files or Information T1059 Command and Scripting Interpreter T1056 Input Capture T1033 System Owner/User Discovery T1016 System Network Configuration Discovery T1046 Network Service Discovery T1547.001 Registry Run Keys / Startup Folder T1074 Data Staged T1057 Process Discovery T1590 Gather Victim Network Information T1047 Windows Management Instrumentation T1056.001 Keylogging T1556 Modify Authentication Process T1608.001 Upload Malware T1071.001 Web Protocols T1059.005 Visual Basic T1555.003 Credentials from Web Browsers T1486 Data Encrypted for Impact T1187 Forced Authentication T1518 Software Discovery T1087 Account Discovery T1614.001 System Language Discovery T1041 Exfiltration Over C2 Channel T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol T1204.001 Malicious Link T1482 Domain Trust Discovery T1027.013 Encrypted/Encoded File T1074.001 Local Data Staging T1036.005 Match Legitimate Resource Name or Location T1027.015 Compression T1102 Web Service T1614 System Location Discovery T1583.006 Web Services

Reporting

Research mentioning SocGholish

Jul 21
Derp Ca

TA2726 turns 1,509 WordPress sites into malware launchpads | Derp

selected Windows users are handed to TA569's SocGholish fake browser update. The lure downloads Google Launcher.js

Jul 12
Cysecurity News

Operation Endgame Disrupts Global Cyber Crime Assembly Line - CySecurity News - Latest Information Security and Hacking Incidents

According to Europol, another tool that disrupted Operation Endgame was SocGholish. It is a malware installer tied to the Russian cybercrime group Evil Corp. that distributes via hacked websites.

Jul 10
Trojan Killer News

WP-SHELLSTORM Webshells Hit WordPress Sites

Trojan Killer recently covered a similar cleanup lesson in the SocGholish WordPress takedown, where the safest response was not only to remove the visible injection but also to rotate credentials and check the admin machines used to manage the site.

Jul 7
Gurucul Threat Research

Millenium: A RAT Rewritten, a Threat Multiplied | Community Portal | Gurucul

SocGholish1

Jun 30
Belgium Ccb Product Advisories

Warning: WordPress sites targeted by botnet to distribute malware | CCB Belgium

This campaign has been heavily driven by the "SocGholish" botnet, which utilizes compromised or stolen credentials to gain administrative access to WordPress environments.

Jun 29
Xakep

Правоохранительные органы нарушили работу инфраструктуры малвари Amadey и StealC - Хакер

Ранее в этом месяце, в ходе этой же фазы операции Endgame, правоохранительные органы вывели из строя инфраструктуру загрузчика SocGholish (он же FakeUpdates и GhoLoader).

Jun 26
Zdnet

Comment l’IA a permis de mettre en lumière les liens entre Amadey ...

L’agence européenne de police a en effet annoncé le démantèlement d’une infrastructure criminelle plus large comprenant également les dropper Amadey et SocGholish.

Jun 25
Techrepublic Com Security

Europol, Microsoft Hit Malware Network Behind 27M Stolen Logins, 140,000 Infected Computers

SocGholish/FakeUpdates: Spread through fake browser or software updates on compromised websites.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.