Score Another One For Operation Endgame
SocGholish, the ‘drive by’ malware-as-a-service group known mostly for fake updates and brute force credential theft, has been disrupted by the international co-op Operation Endgame. I’ve reported on each of these separately in the past, covering SocGholish here, and earlier disruptions carried out by Operation Endgame here. The result of this campaign was the takedown of over a hundred domains in attacker control and the remediation of nearly 15K compromised WordPress sites.
WordPress is one of the largest platforms for deploying websites on the internet, and as such is a common target of threat actors. According to ShadowServer’s article on this disruption, as of June 2026 over 43% of websites are powered by the platform globally, many of them small to medium sized enterprises and individuals. SocGholish, which is also known as DEV-0206, GOLD PRELUDE, Mustard Tempest, TA569 and UNC1543, uses Traffic Direction/Distribution Systems (TDS) to redirect users to hijacked or malware injected secondary sites, usually legitimate but compromised, thus spreading their payload with opportunistic attacks rather than targeted ones. This is what sets SocGholish apart from phishing scammers; it’s less baiting victims and more ambushing them. Additionally the group practices ‘domain shadowing’, whereupon they gain access to the DNS providers and hosts. Infiltrating these processes at the first tier of traffic between sites means they in essence hide behind the legitimacy of these domains, and bypass security measures via exploitation of the established trust in them. Part of the difficulty in pinning SocGholish down has been the rapid turnover in domain cycling which is a hallmark of the group’s infrastructure. Defenders can find one, but the group simply moves on to the next.
This coordinated disruption was carried out last week by authorities from the Netherlands (NHCTU), Canada (RCMP), the United States (FBI) and Germany (BKA), with support from Europol and Eurojust, as well as private sector partners such as Infoblox (who also covered the campaign), Proofpoint and The Shadowserver Foundation. In total, 14,971 compromised legitimate WordPress sites infected with SocGholish malware were remediated and 106 servers and domains were taken down worldwide, disrupting the SocGholish botnet.
Victims of the compromised sites are urged to do the usual hardening of their systems: immediately change their login credentials, enable multi‑factor authentication (MFA/2FA), check for and delete any unknown additional WordPress accounts that have been added, and patch their WordPress site and keep their software and plugins up‑to‑date in the future. Furthermore, ShadowServer has provided a special report site to inform site owners and other potential victims not already notified if they are part of the list of the compromised sites. For everyone else, the same advice applies that always does: don’t click an untrusted link. SocGholish works by tricking users into clicking a popup that then redirects them to a secondary site where they download the malware through an alleged update. Real updates will always come from the vendor or system settings. This disruption is not likely to be the end of the group, but it is a significant win just the same.
Posted, 6/22/26






