惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

N
Netflix TechBlog - Medium
G
Google Developers Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
T
The Blog of Author Tim Ferriss
Microsoft Azure Blog
Microsoft Azure Blog
GbyAI
GbyAI
L
LangChain Blog
云风的 BLOG
云风的 BLOG
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
aimingoo的专栏
aimingoo的专栏
P
Proofpoint News Feed
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
小众软件
小众软件
WordPress大学
WordPress大学
A
About on SuperTechFans
大猫的无限游戏
大猫的无限游戏
C
Check Point Blog
月光博客
月光博客
Stack Overflow Blog
Stack Overflow Blog
美团技术团队
Jina AI
Jina AI
T
Tailwind CSS Blog
Google DeepMind News
Google DeepMind News
D
Docker

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Operation Endgame Disrupts Network Linked to Major Ransom...
https://www.infosecurity-magazine.com/profile/danny-palmer/ · 2026-06-19 · via www.infosecurity-magazine.com

A major cybercriminal network involving thousands of infected websites used to distribute malware has been disrupted by an international law enforcement takedown.

The action against the SocGholish malware group formed the latest part of Operation Endgame, an ongoing global police investigation to combat ransomware and cybercrime worldwide.

Announced by the Dutch police on June 18, action was taken to remediate infections of 15,000 websites controlled by SocGholish group and to dismantle the botnet associated with the group.

Notably, the SocGholish botnet was regularly used by Evil Corp, the notorious, Russia-based ransomware and cyber crime group behind a swath of destructive malware attackers worldwide, including against governments, healthcare institutions and enterprises.

SocGholish hacked or used previously leaked credentials to gain access to legitimate WordPress sites. As detailed by Proofpoint, which tracks SocGholish as TA569, these compromised websites were used to push malicious pop-ups to visitors, which told users that they were using out-of-date software which needed updating.

If the user installed the ‘update’ they became infected with malware and roped into the SocGholish botnet, used to deliver malware and ransomware to further victims.

The international law enforcement has taken action against SocGholish has seen the takedown of 106 servers and domains associated with the malware, as well as remediating infections of the compromised websites.

 'With these actions we deprive cybercriminals of access to infected computer systems. This prevents further damage to the digital systems of citizens, businesses and organizations worldwide and limits the spread of malware,” said Maikel Rollman of the Netherlands National High Tech Crime Unit (NHCTU).

“It also reduces the risk that these systems are used for cyber‑attacks on critical infrastructure and other essential societal processes. This marks the beginning of further action against SocGholish,” he added.

Read more: Why Ransomware Remains One of Cybersecurity's Most Persistent and Costly Threats 

The coordinated action took place over a week was taken jointly by specialist agents and officers at the NHCTU, the Royal Canadian Mounted Police (RCMP), the German Federal Criminal Police Office (BKA) and the US Federal Bureau of Investigation (FBI). The action also received support from Europol, Eurojust and cybersecurity industry partners.

“SocGholish is not a niche threat. Their activities reach deep into public sector and commercial environments, paving the way for other cybercriminals to gain access to networks”, said Dr. Renée Burton, vice president of Infoblox Threat Intel, one of the industry partners which supporting the action.  

The owners of the compromised websites have been informed about what happened and urged to change their login credentials, as well as update the sites with the necessary security patches..

The owners of WordPress sites have also been issued with the following advice:

  • Change their login credentials
  • Enable multi‑factor authentication
  • Delete any unknown additional WordPress accounts
  • Keep their WordPress site up‑to‑date in the future