Back to News
Cybersecurity

Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

Cyber RTJune 19, 20263 min read
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

Dutch law enforcement, alongside Canadian, German, and U.S. counterparts, dismantled SocGholish's malicious infrastructure, cleaning nearly 15,000 infected WordPress sites. Part of Operation Endgame, this effort took down 106 servers linked to SocGholish, a JavaScript-based malware active since 2017. The operation aims to prevent further cyberattacks and malware spread, impacting various sectors globally. Website owners were advised to update security measures.

Dutch law enforcement, in collaboration with agencies from Canada, Germany, and the U.S., has successfully disrupted the malicious infrastructure associated with the SocGholish malware. This operation resulted in the cleanup of nearly 15,000 infected WordPress websites. Maikel Rollman from the Netherlands National High Tech Crime Unit emphasized that these actions prevent further damage to digital systems globally and reduce the risk of cyber attacks on critical infrastructure. This initiative marks the beginning of further actions against SocGholish. The takedown is part of Operation Endgame, an international law enforcement effort aimed at combating botnets and related criminal infrastructures. Launched in 2024, the operation has already led to the dismantling of 106 servers linked to SocGholish and the cleansing of thousands of WordPress sites. Website owners have been advised to update their content management systems, change credentials, and remove any suspicious accounts to prevent future infections. SocGholish, also known as FakeUpdates, is a JavaScript-based downloader malware active since 2017. It serves as a conduit for various next-stage malware from threat actors like Evil Corp, LockBit, and others. The malware is distributed through compromised websites, masquerading as deceptive updates for popular web browsers and software. The operators of SocGholish have been tracked under several aliases, including Gold Prelude and Mustard Tempest. The infection process typically involves compromised websites that have been altered in various ways. According to Silent Push, these infections can occur through direct injections or via intermediate JavaScript files. In November 2025, Arctic Wolf reported that SocGholish was being used by RomCom threat actors to deliver the Mythic Agent, showcasing the malware's broad utilization by various actors with different motivations. Orange Cyberdefense observed that SocGholish infections often deliver loaders like Gholoader and MintsLoader, which lead to additional payloads such as GhostWeaver and LockBit. The malware uses a layered delivery model and collaborates with traffic distribution system operators like TA2726. Many compromised WordPress sites have been modified to include SocGholish's criminal infrastructure, with the majority located in the U.S., followed by other countries like Germany and France. The Shadowserver Foundation highlighted the use of "Domain Shadowing" by SocGholish operators, a technique where threat actors create subdomains under legitimate domains to hide malicious activities. These subdomains blend with legitimate DNS infrastructure, making it difficult for defenders to detect illicit activities. The infected websites are often exploited by multiple threat actors, exposing visitors to various threats based on factors like their location and browser type. SocGholish operates as a multi-stage JavaScript framework, turning compromised websites into drive-by download malware delivery vehicles. This framework involves traffic acquisition, filtering, payload lures, and on-device implant execution. Affiliates play a crucial role in this ecosystem by directing traffic to SocGholish, with prominent affiliates including TA2726 and Parrot TDS. Infoblox reported that 55% of its cloud customers attempted to reach SocGholish infrastructure, indicating its widespread impact across various industries. Overall, SocGholish is not limited to a specific sector but poses a significant threat across multiple industries, including government, education, banking, and healthcare. Its large-scale webinject and TDS ecosystem make it a broadly relevant threat, affecting both public-sector and commercially important environments. The ongoing efforts by international law enforcement agencies aim to mitigate this threat and protect digital systems worldwide.