All incidents

Global takedown of SocGholish malware botnet

malwareclosedJun 19, 2026 — Jun 19, 2026
Global takedown of SocGholish malware botnet

LAW enforcement agencies have disrupted the SocGholish malware botnet in a coordinated international strike, taking down more than a hundred command‑and‑control nodes and protecting thousands of compromised websites. The operation, announced by Dutch police, targeted a network that had been used to push fake browser updates and drive‑by downloads to unsuspecting visitors. By shutting down the infrastructure, authorities aim to curb the ransomware campaigns that Evil Corp has built around this framework. The takedown follows months of surveillance and joint work between the Netherlands, Canada, Germany, the United States and Europol.

SocGholish is a malware framework first seen in 2017 that delivers a variety of payloads through compromised web pages. It typically injects malicious pop‑ups that mimic legitimate software updates, tricking users into downloading executables that give attackers remote access. In this campaign the framework was leveraged by the Russian‑speaking group tracked as DEV‑0206, which is closely affiliated with the Evil Corp ransomware syndicate. Nearly fifteen thousand WordPress sites were found to be hosting the malicious scripts, turning each into a distribution point for the malware.

During the operation authorities seized 106 servers and domains that formed the backbone of the SocGholish command‑and‑control network. The seized assets included hosting providers, domain registrars and virtual private servers spread across multiple jurisdictions. Investigators said the disruption will prevent the malware from contacting its operators and will stop further distribution of the malicious pop‑ups. The effort also involved sharing indicators of compromise with private sector partners to aid in cleaning infected sites.

The botnet had been active for several years, with the first samples appearing in mid‑2017 and a notable resurgence observed in early 2026. Evil Corp has used SocGholish as a staging ground for ransomware payloads such as LockBit and Clop, often demanding multi‑million dollar payments from compromised enterprises. The recent takedown marks one of the most significant blows to the group’s infrastructure in recent memory, potentially delaying their ability to launch large‑scale extortion campaigns.

Website administrators are advised to immediately reset all administrative passwords and enforce multi‑factor authentication on any accounts that control content management systems. They should also update WordPress core, themes and plugins to the latest versions, as outdated components were the primary entry point for the SocGholish injections. Running a full file‑system scan for unknown JavaScript or PHP code and removing any unfamiliar scripts is essential to eradicate lingering threats.

Beyond credential hygiene, organisations should monitor web traffic for unexpected outbound connections to unknown IP addresses or domains, particularly those that match the indicators released by law enforcement. Deploying web application firewalls that can block known malicious user‑agent strings and implementing content security policies will help prevent future injections. Regular backups of site data and databases, stored offline, ensure that recovery is possible even if a server is re‑infected.

Maintaining up‑to‑date security patches, conducting periodic penetration tests and educating staff about social engineering tactics remain core defences against threats like SocGholish. The collaborative nature of this operation shows how cross‑border cooperation can dismantle complex cyber‑criminal networks, but defenders must stay vigilant as threat actors continually adapt their techniques. By applying these measures, site owners can reduce the likelihood of their assets being abused in future malware campaigns.

Intelligence briefing updated Jun 19, 2026

Evil Corp
Root sourcewww.politie.nl
Timeline Coverage

Swipe to explore timeline