Visualização normal

Antes de ontemFirewall Daily – The Cyber Express
  • ✇Firewall Daily – The Cyber Express
  • Operation Endgame Disrupts SocGholish, StealC Malware Networks Samiksha Jain
    Operation Endgame has dealt another blow to cybercriminal operations after international law enforcement agencies and private sector partners dismantled infrastructure supporting the SocGholish, Amadey, and StealC malware families. The coordinated operation resulted in the seizure of more than EUR 41 million in criminal cryptocurrency assets, the recovery of 27 million stolen login credentials, and the disruption of hundreds of servers and domains used to distribute malware. Led by Europol and
     

Operation Endgame Disrupts SocGholish, StealC Malware Networks

Operation Endgame Disrupts SocGholish

Operation Endgame has dealt another blow to cybercriminal operations after international law enforcement agencies and private sector partners dismantled infrastructure supporting the SocGholish, Amadey, and StealC malware families. The coordinated operation resulted in the seizure of more than EUR 41 million in criminal cryptocurrency assets, the recovery of 27 million stolen login credentials, and the disruption of hundreds of servers and domains used to distribute malware.

Led by Europol and Eurojust, the operation brought together authorities from Canada, Denmark, Germany, the Netherlands, the United Kingdom, the United States, Microsoft, and several cybersecurity organizations. Officials said the objective was to disrupt the infrastructure cybercriminals rely on to launch ransomware attacks, financial fraud, and attacks against critical infrastructure.

Operation Endgame Targets Cybercrime Infrastructure

During the coordinated action, authorities targeted the infrastructure supporting malware delivery rather than focusing on a single malware family.

Law enforcement and industry partners took action against 326 servers and 142 domains, significantly disrupting malware distribution channels. Investigators also identified and restricted criminal cryptocurrency assets currently valued at more than EUR 41 million (USD 47 million) while recovering approximately 27 million stolen login credentials.

According to Europol, the operation aimed to disrupt the "assembly line" used by cybercriminals to gain initial access to victim systems before deploying ransomware or stealing sensitive information.

[caption id="attachment_112936" align="aligncenter" width="600"]Operation Endgame Image Soure: Europol[/caption] [caption id="attachment_112937" align="aligncenter" width="600"]Operation Endgame Strikes Malware Image Source: Europol[/caption]

SocGholish, Amadey and StealC Malware Played Different Roles

The operation focused on three malware families that are commonly offered under the cybercrime-as-a-service model.

  • SocGholish functioned as a malware loader that distributed fake browser updates through compromised WordPress websites. Users who installed these fake updates unknowingly infected their systems, allowing attackers to gain initial access and later deploy ransomware or other malicious tools.
  • StealC malware primarily targeted sensitive information stored on infected devices, including passwords, authentication data, and digital identities. The stolen information was later used for fraud or traded within cybercriminal marketplaces.
  • Amadey was mainly distributed through phishing campaigns. It provided attackers with initial access to compromised systems while also offering information-stealing capabilities that enabled the theft of sensitive user data.

Microsoft reported that during the first two weeks of May 2026 alone, Amadey and StealC malware were linked to more than 140,000 infected computers worldwide.

Thousands of Infected WordPress Sites Cleaned

One of the largest actions under Operation Endgame targeted SocGholish, also known as FakeUpdates.

Authorities remediated 14,971 infected WordPress websites, including websites belonging to restaurants, automotive repair businesses, and other organizations. Investigators also disabled the SocGholish botnet by taking control of domains and shutting down supporting servers.

Website owners whose credentials had been exposed were notified through platforms including Have I Been Pwned, DIVD, Spamhaus, CheckjeHack, NoMoreLeaks, Shadowserver, and NL-NCSC.

The Dutch Police urged WordPress administrators to change passwords, enable multi-factor authentication, remove unknown administrator accounts, and keep their websites updated to reduce future compromise risks.

SocGholish Linked to Evil Corp

Authorities said SocGholish has been linked to Evil Corp, a Russian cybercriminal group previously associated with the Zeus and Dridex malware families, as well as multiple ransomware and money laundering operations.

Rather than targeting only malware operators, investigators focused on disrupting the broader infrastructure supporting cybercriminal activity. Europol said this strategy increases operational costs for threat actors and makes large-scale cyberattacks more difficult to execute.

Europol Coordinates Global Cyber Operation

Europol's European Cybercrime Centre (EC3) coordinated operational intelligence sharing through SIENA while providing analytical, technical, and cryptocurrency tracing support throughout the investigation.

The operation forms part of Operation Endgame, described by Europol as the largest international initiative to disrupt ransomware enablers worldwide.

Officials said the latest disruption reflects a growing international strategy of targeting the infrastructure that enables cybercrime operations, rather than responding only after attacks have occurred.
  • ✇Firewall Daily – The Cyber Express
  • Operation Endgame Hits SocGholish Malware Network, 14,971 Websites Cleaned Samiksha Jain
    Operation Endgame Hits SocGholish Malware Network after international law enforcement agencies carried out a coordinated operation targeting one of the most significant malware distribution chains linked to cybercrime. Authorities announced the remediation of 14,971 websites infected with SocGholish Malware, a threat used by the cybercriminal group Evil Corp to gain unauthorized access to victim systems and facilitate further attacks. The operation involved law enforcement agencies from the N
     

Operation Endgame Hits SocGholish Malware Network, 14,971 Websites Cleaned

SocGholish Malware

Operation Endgame Hits SocGholish Malware Network after international law enforcement agencies carried out a coordinated operation targeting one of the most significant malware distribution chains linked to cybercrime. Authorities announced the remediation of 14,971 websites infected with SocGholish Malware, a threat used by the cybercriminal group Evil Corp to gain unauthorized access to victim systems and facilitate further attacks. The operation involved law enforcement agencies from the Netherlands, Canada, the United States, and Germany, with support from Europol and Eurojust. Officials described the action as a major disruption of the infrastructure used to distribute malware through compromised WordPress websites.

Operation Endgame Hits SocGholish Malware Network Across Multiple Countries

During the coordinated action week, authorities took down 106 servers and domains associated with the criminal infrastructure supporting SocGholish operations. According to investigators, SocGholish Malware spreads primarily through compromised WordPress websites. Visitors to infected websites are presented with fake software update prompts, often disguised as browser updates. Once downloaded and installed, the malware establishes access to the victim's system, allowing attackers to deploy additional malicious software. Law enforcement agencies also disabled the SocGholish Botnet by seizing domains and taking servers offline. In addition to infrastructure takedowns, authorities cleaned infected WordPress sites and launched a large-scale victim notification campaign to warn affected website owners and encourage stronger security measures.

WordPress Websites at the Center of the Campaign

Authorities highlighted the widespread use of WordPress as a factor contributing to the scale of the threat. According to WordPress, more than 43% of websites worldwide are built on the platform. Investigators reported that login credentials for approximately 1.4 million websites have been leaked, increasing the risk of unauthorized access and malware infections. Cybercriminals behind SocGholish typically compromise websites by exploiting weak passwords, stolen credentials, or vulnerable website configurations. Once access is obtained, malicious code is inserted into websites, allowing attackers to distribute fake updates to visitors. The infected websites included platforms providing everyday services, such as restaurants and automotive repair businesses.

Authorities Urge Website Owners to Strengthen Security

The Dutch National High Tech Crime Unit stated that malware and backdoors have been removed from affected websites and that site owners have been notified. Website owners have been urged to: Authorities emphasized that these measures can significantly reduce the likelihood of future compromise.

Fake Updates Continue to Drive Infections

Also known as FakeUpdates, SocGholish has remained active since 2017 and continues to be used as an initial access tool for broader cybercriminal operations. The malware is distributed through fraudulent software update messages that appear while users browse compromised websites. Once installed, the malware creates a connection to attackers, enabling them to gain access to victim systems. Officials warned users not to trust browser pop-ups requesting immediate software updates and advised obtaining updates only through official application stores, system settings, or verified vendors. Additional recommendations include maintaining updated antivirus software and exercising caution when encountering urgent update notifications. Law enforcement agencies linked Evil Corp to the SocGholish malware operation. The group has previously been associated with Zeus and Dridex malware campaigns, as well as multiple ransomware and money laundering operations. Authorities noted that SocGholish has been used to deploy various ransomware strains that have impacted organizations and critical infrastructure targets worldwide.

Operation Endgame Expands Global Cybercrime Disruption Efforts

Launched in 2024, Operation Endgame is described by participating agencies as the largest international effort to combat ransomware and cybercrime. The initiative brings together law enforcement and judicial authorities from the Netherlands, Germany, Denmark, the United States, Australia, France, Belgium, the United Kingdom, and Canada, with support from Europol and Eurojust. Officials stated that cooperation between public agencies and private-sector cybersecurity organizations remains a critical component of the operation as efforts continue against SocGholish and other cybercriminal networks.
❌
❌