惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
MongoDB | Blog
MongoDB | Blog
D
Docker
Martin Fowler
Martin Fowler
人人都是产品经理
人人都是产品经理
GbyAI
GbyAI
Jina AI
Jina AI
酷 壳 – CoolShell
酷 壳 – CoolShell
M
MIT News - Artificial intelligence
腾讯CDC
阮一峰的网络日志
阮一峰的网络日志
H
Hackread – Cybersecurity News, Data Breaches, AI and More
N
Netflix TechBlog - Medium
B
Blog RSS Feed
云风的 BLOG
云风的 BLOG
Blog — PlanetScale
Blog — PlanetScale
Vercel News
Vercel News
The Cloudflare Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
有赞技术团队
有赞技术团队
G
Google Developers Blog
Stack Overflow Blog
Stack Overflow Blog
I
InfoQ
U
Unit 42

Hackread – Cybersecurity News, Data Breaches, AI and More

Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity LastPass Confirms Customer Data Breach After Klue OAuth Token Theft ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections Nintendo America Employee Data Exposed After Shadowbyt3$ Targets TinyPulse eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites MacBook Neo vs Windows Laptops for Cybersecurity Tasks What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It
Operation Endgame Disrupts SocGholish Malware Infrastructure
Deeba Ahmed · 2026-06-19 · via Hackread – Cybersecurity News, Data Breaches, AI and More

Operation Endgame has expanded its reach by dismantling the network infrastructure of TA569, a major cybercriminal syndicate.

On 18 June 2026, international law enforcement agencies, including the Netherlands National High-Tech Crime Unit (NHCTU), the Royal Canadian Mounted Police (RCMP), the US Federal Bureau of Investigation (FBI), and Germany’s Federal Criminal Police Office (BKA), with operational support from Europol, announced the successful disruption of the group responsible for the SocGholish malware framework.

This joint action marks the latest phase of the ongoing global campaign targeting initial access brokers and botnets that feed ransomware networks. This development follows threat intelligence provided by Proofpoint, which was shared with Hackread.com.

Anatomy of the Web Inject Attacks

Proofpoint research reveals that this group uses the web injection method to deploy malware on legitimate, high-traffic websites. They can target any website for this purpose- from retail to news platforms. The next step involves gaining privileged access to content management systems (CMS) like WordPress either by using stolen credentials or exploiting vulnerabilities in unpatched plugins.

The SocGholish framework operates via a multi-stage attack chain. First, a script profiles the visitor’s environment to verify the visitor is a real person and not an automated security sandbox. It does this by tracking at least ten mouse movements. It also checks that the user does not have developer tools open.

If everything matches, the script uses a traffic distribution system like ParrotTDS or a Keitaro service run by TA2726 to route the user. The victim then sees a FakeUpdates screen that impersonates a normal browser update alert. Clicking this button runs a hidden iframe that downloads GhoLoader, a first-stage JScript downloader.

TA569 infected landing page (Credit: Proofpoint)

TA569 then tries to ensure persistence on the site. This is achieved by installing fake plugins and PHP backdoors. These are the same initial access points that allowed ransomware groups like Evil Corp, LockBit, RansomHub, and WastedLocker to obtain deeper access to corporate networks in the past.

According to Dutch Police’s press release, to break this specific ransomware pipeline, the global coalition behind Operation Endgame aimed its recent enforcement actions directly at these access points. By taking down the core infrastructure feeding these networks, officials seized over 100 command-and-control (C2) servers and remediated 14,971 such compromised websites.

Operation Endgame video on take take down of the SocGholish infrastructure

A History of Fighting Botnets

This latest crackdown is one of the many past achievements made through Operation Endgame. Hackread.com has covered Operation Endgame over the last couple of years.

In May 2024, the operation resulted in seizing around 100 servers belonging to dropper networks, including IcedID, SystemBC, Smokeloader, Trickbot, Pikabot, and Bumblebee, and by May 2025, the DanaBot network was dismantled, leading to charges against 16 people.

Later in November 2025, police shut down over 1,025 servers used by three other malware groups, terminating the core infrastructure of the Rhadamanthys infostealer, the VenomRAT remote control tool, and the Elysium botnet.

Most recently, in January 2026, Dutch police arrested the 33-year-old mastermind behind a hacker testing site at Amsterdam’s airport. Nevetheless, experts believe this latest hit on SocGholish will cause severe financial and reputational damage to the TA569 group, making the internet safer for everyone.