Operation Endgame Takes Down SocGholish: 106 Servers Seized, 15,000 Sites Cleaned

International law enforcement has dismantled the SocGholish malware network, seizing 106 servers and 101 domains, and remediating nearly 15,000 infected WordPress sites globally. The operation is part of the ongoing Operation Endgame, targeting Evil Corp-linked infrastructure.

Layla Haddad
Cyber Policy & Digital Risk Correspondent4 min read
Decommissioned server equipment in a data centre corridor, representing the law enforcement seizure of SocGholish botnet infrastructure across 106 servers during Operation Endgame

Decommissioned server equipment in a data centre corridor, representing the law enforcement seizure of SocGholish botnet infrastructure across 106 servers during Operation Endgame

Law enforcement agencies across four countries have executed a coordinated takedown of the SocGholish malware network, seizing 106 servers and 101 domains while remediating nearly 15,000 infected websites worldwide. The operation, conducted by the Netherlands' National High Tech Crime Unit, Canada's Royal Canadian Mounted Police, the United States Federal Bureau of Investigation, and Germany's Bundeskriminalamt, with coordination from Europol and Eurojust, forms part of Operation Endgame, the ongoing international effort against ransomware and cybercrime infrastructure that launched in 2024 and has been recognised as the largest international operation ever conducted against this class of threat.

"With these actions we deprive cybercriminals of access to infected computer systems," said Maikel Rollman of the NHTCU. "This prevents further damage to the digital systems of citizens, businesses and organisations worldwide and limits the spread of malware. It also reduces the risk that these systems are used for cyber attacks on critical infrastructure and other essential societal processes. This marks the beginning of further action against SocGholish."

What SocGholish is and how it works

SocGholish, also known as FakeUpdates, is a JavaScript-based malware framework that has been active since 2017. The group's operational methodology is straightforward but effective at scale: threat actors inject malicious JavaScript into legitimate but compromised websites, primarily WordPress installations, where it presents visitors with convincing fake browser update prompts.

When a user downloads and executes the presented fake update file, the malware establishes a backdoor connection to attacker-controlled infrastructure. From that foothold, the operators or their affiliates can deploy a range of secondary payloads including remote access trojans, infostealers, Cobalt Strike beacons, and ransomware. SocGholish is formally attributed to Evil Corp, the Russian cybercriminal syndicate previously responsible for the Zeus and Dridex banking trojans.

The scale of the remediated compromise is significant. Authorities confirmed that 14,971 websites were actively infected and have been cleaned, including small business sites spanning restaurants, garages, and other everyday services. Login credentials for approximately 1.4 million WordPress websites were leaked in connection with the campaign, leaving those sites susceptible to malware injection even if not yet actively compromised.

Affected site owners were notified through trusted partner platforms including HaveIBeenPwned, DIVD, Spamhaus, The Shadowserver Foundation, and the NCSC Netherlands. They have been urged to rotate login credentials, enable multi-factor authentication, and audit all administrator accounts for unauthorised access.

What GCC web administrators and security teams must do

WordPress powers more than 43 per cent of all websites globally, and its penetration in the GCC is significant across commercial, government-adjacent, and media properties. The SocGholish takedown removes the specific infrastructure behind this campaign but does not remove the risk to WordPress installations that remain unpatched, use compromised credentials, or carry outdated plugins.

For web administrators and IT security teams in the UAE and Saudi Arabia operating WordPress-based properties, the following actions are appropriate immediate responses. Rotate all WordPress administrator passwords and revoke any unrecognised administrator accounts. Enable multi-factor authentication on all admin accounts. Verify that the core WordPress installation, active themes, and all plugins are updated to their current versions. Review web server access logs for evidence of requests matching SocGholish's known injection pattern or delivery paths. Conduct a review of any third-party JavaScript loaded by the site, as injected scripts frequently appear in theme files, plugin directories, or wp-content areas.

The broader significance of Operation Endgame

The SocGholish action follows earlier Endgame phases that disrupted loaders including Bumblebee, IcedID, SystemBC, and Pikabot. The sustained focus of the operation signals a shift in law enforcement strategy from one-off takedowns towards sustained, iterative pressure against the infrastructure layers that enable ransomware deployment.

For enterprise security professionals tracking threat actor capability, the disruption of SocGholish removes one of the most prolific initial access brokers from active operation, at least temporarily. The history of prior Endgame targets suggests that successor infrastructure typically re-emerges within months, but the operational cost imposed on the threat actor group and the loss of 106 servers and 101 domains represents a meaningful setback to the broader Evil Corp ecosystem.

Layla Haddad

Cyber Policy & Digital Risk Correspondent

Layla Haddad covers cybersecurity regulations, data protection laws, and digital transformation initiatives across GCC and North Africa. She has worked closely with compliance teams, fintech startups, and government advisory groups. Her articles explore how cyber policy, AI governance, and privacy frameworks shape the region’s digital future.

Intelligence Focus Areas

Ransomware Ecosystem 2026International Cyber Law EnforcementWeb Application Security GCCCybercrime Infrastructure Takedown