HomeSecurityOperation Endgame: Dismantling the SocGholish malware distribution network

Operation Endgame: Dismantling the SocGholish malware distribution network

One of the most significant international cybercrime operations is in full swing, as security authorities from multiple countries have succeeded in disrupting the notorious SocGholish malware. The operation, known as Operation Endgame, led to the restoration of nearly 15,000 infected websites and the weakening of an infrastructure that had been used for years to infiltrate corporate networks and prepare ransomware attacks.

Operation Endgame SocGholish

According to authorities, SocGholish is linked to the criminal organization Evil Corp, one of the most well-known cybercrime groups worldwide, which has been linked in the past to banking trojans, ransomware attacks, and extensive money laundering operations.

Operation Endgame: Coordinated operation in many countries

The operation involved law enforcement agencies from the United States, Canada, Germany and the Netherlands, with support from Europol and Eurojust. During the coordinated action, 106 servers and domainsused to distribute the malware and manage the infected systems were seized or taken down.

See also: SocGholish Malware: Exploits the BOINC project to carry out cyberattacks

At the same time, the authorities proceeded to restore 14,971 websites, which had been hacked and turned, without the knowledge of their owners, into platforms for the dissemination of SocGholish.

The operation is considered particularly important, as it was not limited to seizing the criminal infrastructure, but also aimed to interrupt the chain of infection that fueled broader cybercriminal activities.

How SocGholish works

SocGholish, also known as FakeUpdates, emerged in 2017 and remains to this day one of the most effective initial access tools used by cybercriminals.

Its operation is based on user deception. When a visitor enters a compromised website, a pop-up window appears informing them that their browser or some software needs an immediate update. In reality, the supposed update contains malicious code.

After the user installs the fake update file, attackers gain remote access to the system and can install additional malware, steal data, or prepare to deploy ransomware.

Operation Endgame: Dismantling the SocGholish malware distribution network

WordPress at the center of attacks

Interestingly, the bulk of the campaign was based on compromised WordPress sites. Given that more than 43% of websites worldwide use the platform, cybercriminals found an extremely large field of action.

See also: Operation Endgame 2.0: Authorities “hit” malware businesses

Researchers estimate that access credentials for approximately 1.4 million websites have been leaked online, significantly increasing the risk of new breaches.

The attackers are primarily exploiting weak passwords, stolen login credentials, and poorly updated WordPress installations. Even small businesses, such as restaurants, auto repair shops, and local stores, have been targeted in the campaign.

The authorities' recommendations to website administrators

The competent authorities are calling on website owners to immediately strengthen their security measures. Key recommendations include changing all passwords, activating Multi-Factor Authentication (MFA), deleting unknown administrator accounts, and keeping the platform and additional applications fully updated.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Experts emphasize that many attacks could have been prevented through basic cybersecurity practices. Delayed security updates and the use of weak passwords are still two of the most important causes of website breaches.

See also: Abuse of Google Ads, GitLab and Claude to distribute malware

Operation Endgame: Dismantling the SocGholish malware distribution network

The fight against ransomware continues

Authorities point out that SocGholish is not just another piece of malware. It is a critical link in a cybercrime chain that has led to numerous attacks ransomware against businesses and critical infrastructure around the world.

Operation Endgame, launched in 2024, is already being billed as the largest international initiative to combat ransomware and organized cybercrime networks. However, experts warn that weakening an infrastructure does not mean eliminating the threat altogether.

Continuous cooperation between government authorities, cybersecurity companies and digital infrastructure managers is now considered a prerequisite, as cybercriminal organizations are constantly evolving and looking for new ways to exploit the weaknesses of the global digital ecosystem.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS