Threats · 87 days ago
SocGholish Takedown Leaves Reinfectable CMS Estates The backbone is gone, but the real risk is now in the websites that were already compromised. Taking down SocGholish servers stops the current delivery network, yet stolen CMS credentials and unpatched WordPress, Joomla, or Drupal sites can be used to bring the same access path back.
Authorities in the Netherlands, Canada, the US, and Germany, with Europol support, seized 106 SocGholish servers and domains and disinfected about 15,000 infected WordPress sites. Site owners whose credentials were identified were told to change logins, enable MFA, delete suspicious accounts, and keep their CMS updated; SocGholish itself has long spread through fake browser-update prompts on legitimate sites.
That makes this a cleanup handoff, not a finish line. The infrastructure seizure reduces immediate distribution, but the compromised CMS layer can still be reused for reinfection and follow-on abuse if access and hidden persistence are not removed.
Timeline Sources 8 sources covering this story
The Hacker News Jun 19
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
Authorities took down 106 SocGholish servers and cleaned 14,971 infected WordPress sites under Operation Endgame.
The Record from Recorded Future Jun 19
Police raid malware network tied to Russia's Evil Corp hacker group
An international operation targeted the SocGholish botnet, which has been linked to the Russia-based cybercrime group Evil Corp.
Infosecurity Magazine Jun 19
Operation Endgame Disrupts Network Linked to Major Ransomware Gang
SocGholish malware has been removed from 15,000 sites associated with Evil Corp hackers
SecurityWeek Jun 19
15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown
Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame.
CyberScoop Jun 19
Authorities disrupt Evil Corp’s SocGholish botnet
Cybersecurity firms, researchers and officials took down 106 servers and remediated nearly 15,000 sites that were infected with the malware.
Shadowserver Foundation Jun 18
SocGholish Compromised WordPress Sites Special Report
High level analysis of compromised WordPress sites is provided.
Help Net Security Jun 18
Law enforcement hits SocGholish: 106 servers down, 15,000 sites cleaned - Help Net Security
SocGholish, an operation that's been delivering malware to users via fake software updates, has suffered a major blow.
BleepingComputer Jun 18
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group.
Entities Part of the PlainSec briefing for 2026-06-20
Editions Related stories
Threats · 87 days ago
SocGholish Takedown Leaves Reinfectable CMS Estates The backbone is gone, but the real risk is now in the websites that were already compromised. Taking down SocGholish servers stops the current delivery network, yet stolen CMS credentials and unpatched WordPress, Joomla, or Drupal sites can be used to bring the same access path back.
Authorities in the Netherlands, Canada, the US, and Germany, with Europol support, seized 106 SocGholish servers and domains and disinfected about 15,000 infected WordPress sites. Site owners whose credentials were identified were told to change logins, enable MFA, delete suspicious accounts, and keep their CMS updated; SocGholish itself has long spread through fake browser-update prompts on legitimate sites.
That makes this a cleanup handoff, not a finish line. The infrastructure seizure reduces immediate distribution, but the compromised CMS layer can still be reused for reinfection and follow-on abuse if access and hidden persistence are not removed.
Timeline Sources 8 sources covering this story
The Hacker News Jun 19
Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites
Authorities took down 106 SocGholish servers and cleaned 14,971 infected WordPress sites under Operation Endgame.
The Record from Recorded Future Jun 19
Police raid malware network tied to Russia's Evil Corp hacker group
An international operation targeted the SocGholish botnet, which has been linked to the Russia-based cybercrime group Evil Corp.
Infosecurity Magazine Jun 19
Operation Endgame Disrupts Network Linked to Major Ransomware Gang
SocGholish malware has been removed from 15,000 sites associated with Evil Corp hackers
SecurityWeek Jun 19
15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown
Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame.
CyberScoop Jun 19
Authorities disrupt Evil Corp’s SocGholish botnet
Cybersecurity firms, researchers and officials took down 106 servers and remediated nearly 15,000 sites that were infected with the malware.
Shadowserver Foundation Jun 18
SocGholish Compromised WordPress Sites Special Report
High level analysis of compromised WordPress sites is provided.
Help Net Security Jun 18
Law enforcement hits SocGholish: 106 servers down, 15,000 sites cleaned - Help Net Security
SocGholish, an operation that's been delivering malware to users via fake software updates, has suffered a major blow.
BleepingComputer Jun 18
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group.
Entities Part of the PlainSec briefing for 2026-06-20
Editions Related stories