home.social

#socgholish — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #socgholish, aggregated by home.social.

fetched live
  1. Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

    Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.

    Pulse ID: 6a7ec3107e8b34f88b5d610e
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: AlienVault
    Created: 2026-08-14 07:26:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault

  2. Not the right person to action this yourself? ➡️ Forward this to whoever handles abuse reports or security escalations at your company.

    It takes less than 5 minutes to pull the list and get started 🙏

    #Trustandsafety #SocGholish #Remediation

    3/3