Threats · 83 days ago
The real target was the delivery network, not just one malware framework. Seizing 106 servers and remediating 14,971 compromised WordPress-heavy sites disrupted the broker that funneled users into fake browser-update lures.
SocGholish has long served as an initial-access service for groups like Evil Corp. The cut hurts distribution, but the compromised sites show how broad and reusable the channel is, which is why blocking one domain is never the full response.
1 source covering this story
SocGholish Takedown Highlights Malicious TDS Threats
SocGholish uses traffic distribution systems (TDSs) to provide initial access into victims' networks for cybercrime groups such as the notorious Evil Corp.
Part of the PlainSec briefing for 2026-06-23