Last seven days
- First activity
- Aug 29, 2026
- Last activity
- Sep 5, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 449 hostnames
SocGholish, also known as FakeUpdates, is a Windows-focused JavaScript malware delivery framework and initial-access service active since at least 2017–2018.
Profile source: Mallory opens in a new tabSocGholish
SocGholish, also known as FakeUpdates, is a Windows-focused JavaScript malware delivery framework and initial-access service active since at least 2017–2018. It compromises legitimate websites, including WordPress sites accessed using stolen administrator credentials, and injects scripts that selectively redirect visitors to fraudulent browser or software-update pages. Victims are socially engineered to download and execute archives, JavaScript, or HTA content masquerading as updates. The loader profiles hosts, collects system and security-product information, performs anti-analysis checks, and uses Windows command interpreters or PowerShell to retrieve and launch follow-on payloads. SocGholish has delivered Cobalt Strike, NetSupport RAT, Dridex, banking malware, information stealers, and ransomware-enabling tooling, and has been used as a precursor to targeted ransomware incidents involving WastedLocker and LockBit. It is widely associated with the Indrik Spider/Evil Corp cybercriminal ecosystem, although delivery and access-broker partnerships can involve other actors. Campaigns use compromised websites, drive-by downloads, watering-hole activity, malicious advertising, and occasionally spam links to compromised sites; targeting commonly prioritizes first-time Windows visitors arriving through search engines or other third-party referrers.
C2 tracking
Derp observations, rolling seven-day window
Samples
891cd20daf021cfc407281667be16abf6c6f7ae333d179c3c0b75df4e9d649b0 c161fa35e407f58a4d2310593afdca1c74f8212f5c523af0644a13cc8dce70d2 483da5618c97e4734bfd95b26d978048326801f39ab8e8a6f6c0558f1097866d fe408c1e4d27dafd385d12c1a2d689a867e6b9e8d4378d12e5d1405e19900a5a ffa74b6ece2e3b18f7a5cf5d9c51a48b8a25ee8372831243741ec8250ea4a793 25d9f7afe0fe982d1661cc90301128498cd296bb93566aca408cdb944b219ad0 5b5b7d9bf75938c0d6ac3dfe05735d4fb6442b33236d7ee88684f0b08744bea9 c776ba49f7db2567e2486b1324f080067a7524357ee9e566e579f4dd3a67d990 3e3439f1a265e3fd551e4cae709d162668c25bf5a1f8cfdc2633df85292ba0da df5448c015a221273d93fdd5fab628551682143f3314f966d1298a210a4182c2 Reported operators
Shady Squirrel ... sends traffic to initial access brokers and cybercriminals like SocGholish ... SocGholish is believed to have regained access to thousands of compromised sites by teaming up with the threat actor merely days after its infrastructure was disrupted in a law enforcement operation.
SocGholish is an advanced delivery framework used in drive-by-download and watering hole attacks... First seen in the wild in April 2018, SocGholish is a drive-by-download framework used in social engineering attacks to deliver a range of remote access trojans and ransom tools.
This NDSW/NDSX malware — also referred to as FakeUpdates or SocGholish by other research groups — is responsible for redirecting site visitors to malicious pages designed to trick victims into loading and installing fake browser updates.
The tech giant said it observed the FakeUpdates (aka SocGholish) malware being delivered via existing Raspberry Robin infections on July 26, 2022.
Recorded Future exploits TDS to demonstrate a high-level activity strategy that includes regularly updating URLs embedded in WordPress sites, adding additional servers, and improving TDS logic to evade detection, and has been linked to SocGholish and D3F@ck Loader malware, as well as the Rhysida and Interlock ransomware groups.
Active since 2017 and also known as FakeUpdates, SocGholish is a JavaScript (JS)-based downloader malware that typically serves as a conduit for next-stage malware from various threat actors like Evil Corp, LockBit, RansomHub, Dridex, and Raspberry Robin.
Active since 2017 and also known as FakeUpdates, SocGholish is a JavaScript (JS)-based downloader malware that typically serves as a conduit for next-stage malware from various threat actors like Evil Corp, LockBit, RansomHub, Dridex, and Raspberry Robin.
TAG-124 has also been associated with SocGholish and D3F@ck loader malware, which provide remote access and malware delivery for financially motivated activity.
A coordinated SocGholish (FakeUpdates) campaign wave launched 2026-03-02 deployed 11 stage-1 JavaScript injectors across 6 distinct C2 domains hosted by 4 providers spanning Panama, the United States, and Canada.
A coordinated SocGholish (FakeUpdates) campaign wave launched 2026-03-02 deployed 11 stage-1 JavaScript injectors across 6 distinct C2 domains hosted by 4 providers spanning Panama, the United States, and Canada.
"SocGholish, also called FakeUpdates, is a JavaScript loader malware that's distributed via compromised websites by masquerading as deceptive updates for web browsers like Google Chrome or Mozilla Firefox..."
SocGholish, operated by TA569, actually functions as a Malware-as-a-Service (MaaS) vendor, selling access to compromised systems to various financially motivated cybercriminal clients. The primary tactic used involves deceptive “fake browser update” lures...
SocGholish, operated by TA569, actually functions as a Malware-as-a-Service (MaaS) vendor, selling access to compromised systems to various financially motivated cybercriminal clients. The primary tactic used involves deceptive “fake browser update” lures...
SocGholish, operated by TA569, actually functions as a Malware-as-a-Service (MaaS) vendor, selling access to compromised systems to various financially motivated cybercriminal clients. The primary tactic used involves deceptive “fake browser update” lures...
"Throughout 2024 we continued to observe a low volume of SocGholish infections... upon execution the JavaScript payload connects back to SocGholish infrastructure... and can retrieve additional malware."
“VexTrio Viper runs the largest and oldest known TDS with over 165 affiliates including SocGholish and ClearFake.”
Arctic Wolf Labs assesses with a medium-to-high confidence level that Russia’s GRU unit 29155 is utilizing SocGholish to target victims. .. Actor: TA569 is considered the primary threat actor deploying and maintaining SocGholish... The operator serves as an Initial Access Broker (IAB), selling access to compromised systems to ransomware affiliates.
Exploited software
MITRE ATT&CK
Reporting
A Sonatype report identified six malicious npm packages that used Ethereum transactions to retrieve and stage malicious payloads, an unusual delivery method that obscures second-stage infrastructure behind blockchain activity. The campaign was linked in public reporting to ContagiousInterview and NullReceiver, indicating continued abuse of the JavaScript and Node.js ecosystem for software supply-chain compromise. The activity aligns with broader attacker tradecraft documented for MITRE ATT&CK T1059.007 (Command and Scripting Interpreter: JavaScript), which covers JavaScript and Node.js use for payload delivery, execution, reconnaissance, and command-and-control. Defenders monitoring follow-on behavior should watch for suspicious child-process activity and discovery commands launched from non-shell parent processes, a pattern reflected in Splunk detection guidance for tools such as ipconfig.exe, systeminfo.exe, net.exe, and whoami.exe executed outside normal cmd.exe or PowerShell chains.
The Qilin ransomware group claimed multiple new victims across the United States, Canada, Austria, and Germany, hitting organizations in manufacturing, professional services, financial services, media, retail, property management, and utilities. Named victims included Community Management Associates, Pointe Property Group, Ceragres, Dienst Pack Systems, Schreiner Trockenbau GmbH, Commercial Furniture Interiors, The Saturday Evening Post, Wire Products, Freedom Claims Management, and Service Electric. Several reports described the incidents as both ransomware attacks and associated data breaches, indicating continued emphasis on extortion through stolen data as well as operational disruption. Separate reporting tied Qilin affiliates to active exploitation of Internet-facing VPN and firewall infrastructure, including Palo Alto GlobalProtect CVE-2026-0257 and Check Point VPN CVE-2026-50751, as part of broader mid-2026 ransomware access campaigns. That activity was reported alongside common post-compromise tradecraft such as Impacket, NTLM relay, Mimikatz, PsExec, RDP, WMI, browser credential theft, and use of WSL for EDR evasion. A weekly ransomware trend report counted Qilin among the most active groups, with 31 claimed victims during the period, reinforcing its position as a leading extortion threat affecting organizations across sectors and regions.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.