惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

有赞技术团队
有赞技术团队
小众软件
小众软件
The Cloudflare Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园_首页
酷 壳 – CoolShell
酷 壳 – CoolShell
爱范儿
爱范儿
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
Jina AI
Jina AI
博客园 - 【当耐特】
V
Visual Studio Blog
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
量子位
IT之家
IT之家
G
Google Developers Blog
V
V2EX
The GitHub Blog
The GitHub Blog
月光博客
月光博客
GbyAI
GbyAI

The Record from Recorded Future News

Taiwan charges two businessmen over alleged role in Chinese espionage campaign Former UK privacy chief preparing legal action against woman who reported him, minister says Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip EU unveils cyber plan to reduce reliance on foreign AI systems Supreme Court allows Texas app law requiring age verification to take effect Britain plans to build autonomous AI 'Cyber Shield' to defend nation Major Japanese telco says cyberattack exposed 12 million emails UK cyber pledge draws only a handful of top firms despite ministerial appeal Canadian spy agency reports hacking three criminal groups in 2025 Attackers vote themselves $20 million in BONK cryptocurrency Major medical device manufacturer notifies nearly 4 million of breach Japanese teen arrested over cyberattack that disrupted anime streaming service Ukrainian media outlets now among 'priority targets' for Russian hackers Spyware found on phone of European Parliament member probing it Launch of UK's National Cyber Action Plan delayed amid Labour leadership crisis Supreme Court decision threatens EU-US data transfer agreement Teen suspect in Scattered Spider hacks is extradited to US US lifts export controls on Anthropic’s frontier cybersecurity AI models Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches CIA chief highlights major shifts in agency’s tech approach House passes kids’ online safety bill, but Senate approval unlikely An intelligence budget 'super user' job is now in the hands of Russ Vought Justices rule that cellphone location histories are protected by the Fourth Amendment US racks up about 400 wins over illegal World Cup streaming sites US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp Ukraine to use seized crypto from cybercrime group to buy war bonds Russia accuses Apple of ‘political censorship’ after VK apps removed from App Store Turla group adds more malware to Russia’s espionage efforts against Ukraine Russia used social engineering to breach prominent messaging accounts, Ukraine says FCC votes to toughen rules in bid to better protect undersea cables
Police raid malware network tied to Russia's Evil Corp ha...
Daryna Antoniuk · 2026-06-19 · via The Record from Recorded Future News

An international law enforcement operation has disrupted a malware network linked to the Russia-based cybercrime group Evil Corp, taking down more than 100 servers and disinfecting nearly 15,000 hacked websites used to spread malicious software.

Authorities from the Netherlands, Canada, the United States and Germany said Thursday they dismantled key parts of the SocGholish botnet by seizing domain names and shutting down servers used to infect visitors to legitimate websites, including those of small businesses such as restaurants and auto repair shops.

Dutch police said they also removed malware and backdoors from thousands of infected WordPress websites and notified their owners of the compromise.

SocGholish, also known as FakeUpdates, has been active since 2017 and spreads through fake browser or software update prompts displayed on otherwise legitimate sites. Once installed, the malware allows attackers to deploy additional malicious tools.

"The malware establishes an initial foothold into victim computers, collectively known as a botnet, and is then used by threat actors for further targeting with ransomware campaigns and espionage," the FBI's Cyber Division said in a statement.

First identified in 2017, SocGholish has long been associated with Evil Corp, one of Russia's most notorious cybercrime groups. The threat actor was sanctioned by the United States in 2019 for its role in developing and distributing the Dridex banking malware, which U.S. authorities said caused more than $100 million in financial losses worldwide.

Researchers at cybersecurity firm Infoblox, which assisted with the operation, said SocGholish has also served as an entry point for multiple ransomware groups, including DoppelPaymer, WastedLocker, Hades, LockBit and RansomHub.

Maikel Rollman of the Dutch National High Tech Crime Unit said the operation deprived cybercriminals of access to infected computer systems, helping prevent further harm to individuals, businesses, and organizations worldwide while limiting the spread of malware.

"This marks the beginning of further action against SocGholish," he added.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.