Minacce · 102 giorni fa
La rete cade, ma i CMS compromessi restano esposti Il taglio dell’infrastruttura non chiude il caso: la parte che continua a fare danno sono i siti WordPress, Joomla e Drupal già compromessi, perché credenziali rubate e patch mancanti possono riaprire la stessa porta anche senza i server del botnet. Qui la risposta standard — contare i server sequestrati — perde il punto: la bonifica vera è sugli account e sugli ambienti CMS rimasti in mano all’avversario.
Le autorità hanno sequestrato 106 server e domini legati a SocGholish e hanno ripulito circa 15.000 siti CMS infetti, avvisando i proprietari di cambiare credenziali e rimettere in ordine i sistemi. SocGholish, usato anche come vettore per Evil Corp, si appoggia a siti legittimi già compromessi; le pagine infette mostrano finte richieste di aggiornamento del browser e arrivano spesso da login rubati o vulnerabilità note.
Per chi gestisce siti web, il rischio non finisce con il takedown: se CMS, account e accessi nascosti non vengono bonificati, la stessa infrastruttura può essere ricostruita altrove e tornare a servire malware.
Cronologia Fonti 8 fonti che coprono questa storia
The Hacker News 19 giu
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
Authorities took down 106 SocGholish servers and cleaned 14,971 infected WordPress sites under Operation Endgame.
The Record from Recorded Future 19 giu
Police raid malware network tied to Russia's Evil Corp hacker group
An international operation targeted the SocGholish botnet, which has been linked to the Russia-based cybercrime group Evil Corp.
Infosecurity Magazine 19 giu
Operation Endgame Disrupts Network Linked to Major Ransomware Gang
SocGholish malware has been removed from 15,000 sites associated with Evil Corp hackers
SecurityWeek 19 giu
15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown
Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame.
CyberScoop 19 giu
Authorities disrupt Evil Corp’s SocGholish botnet
Cybersecurity firms, researchers and officials took down 106 servers and remediated nearly 15,000 sites that were infected with the malware.
Shadowserver Foundation 18 giu
SocGholish Compromised WordPress Sites Special Report
High level analysis of compromised WordPress sites is provided.
Help Net Security 18 giu
Law enforcement hits SocGholish: 106 servers down, 15,000 sites cleaned - Help Net Security
SocGholish, an operation that's been delivering malware to users via fake software updates, has suffered a major blow.
BleepingComputer 18 giu
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group.
Entità Part of the PlainSec briefing for 2026-06-20
Editions Storie correlate
Minacce · 102 giorni fa
La rete cade, ma i CMS compromessi restano esposti Il taglio dell’infrastruttura non chiude il caso: la parte che continua a fare danno sono i siti WordPress, Joomla e Drupal già compromessi, perché credenziali rubate e patch mancanti possono riaprire la stessa porta anche senza i server del botnet. Qui la risposta standard — contare i server sequestrati — perde il punto: la bonifica vera è sugli account e sugli ambienti CMS rimasti in mano all’avversario.
Le autorità hanno sequestrato 106 server e domini legati a SocGholish e hanno ripulito circa 15.000 siti CMS infetti, avvisando i proprietari di cambiare credenziali e rimettere in ordine i sistemi. SocGholish, usato anche come vettore per Evil Corp, si appoggia a siti legittimi già compromessi; le pagine infette mostrano finte richieste di aggiornamento del browser e arrivano spesso da login rubati o vulnerabilità note.
Per chi gestisce siti web, il rischio non finisce con il takedown: se CMS, account e accessi nascosti non vengono bonificati, la stessa infrastruttura può essere ricostruita altrove e tornare a servire malware.
Cronologia Fonti 8 fonti che coprono questa storia
The Hacker News 19 giu
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
Authorities took down 106 SocGholish servers and cleaned 14,971 infected WordPress sites under Operation Endgame.
The Record from Recorded Future 19 giu
Police raid malware network tied to Russia's Evil Corp hacker group
An international operation targeted the SocGholish botnet, which has been linked to the Russia-based cybercrime group Evil Corp.
Infosecurity Magazine 19 giu
Operation Endgame Disrupts Network Linked to Major Ransomware Gang
SocGholish malware has been removed from 15,000 sites associated with Evil Corp hackers
SecurityWeek 19 giu
15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown
Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame.
CyberScoop 19 giu
Authorities disrupt Evil Corp’s SocGholish botnet
Cybersecurity firms, researchers and officials took down 106 servers and remediated nearly 15,000 sites that were infected with the malware.
Shadowserver Foundation 18 giu
SocGholish Compromised WordPress Sites Special Report
High level analysis of compromised WordPress sites is provided.
Help Net Security 18 giu
Law enforcement hits SocGholish: 106 servers down, 15,000 sites cleaned - Help Net Security
SocGholish, an operation that's been delivering malware to users via fake software updates, has suffered a major blow.
BleepingComputer 18 giu
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group.
Entità Part of the PlainSec briefing for 2026-06-20
Editions Storie correlate