#socgholish — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #socgholish, aggregated by home.social.
-
Not the right person to action this yourself? ➡️ Forward this to whoever handles abuse reports or security escalations at your company.
It takes less than 5 minutes to pull the list and get started 🙏
#Trustandsafety #SocGholish #Remediation
3/3
-
Not the right person to action this yourself? ➡️ Forward this to whoever handles abuse reports or security escalations at your company.
It takes less than 5 minutes to pull the list and get started 🙏
#Trustandsafety #SocGholish #Remediation
3/3
-
📢 ENDGAME REMEDIATION - SOCGHOLISH | Following last week’s announcement and today’s update from Europol (link below), the disruption effort against SocGholish has expanded to include Amadey and StealC.
Spamhaus is now sending notification emails 📩 to hosters of confirmed compromised WordPress sites.
Here's what to do if you receive one:
👉 Go to this remediation webpage: https://www.spamhaus.org/endgame-socgholish
👉 Enter the access code included in the email
👉 Download the list of compromised WordPress administrator credentials
👉 Verify and where necessary, contact the owner to update their credentials, enable multi-factor authentication, remove any unrecognised WordPress accounts, and ensure your WordPress installation is fully up to date. (there's a ready-made email template for you to use on the remediation webpage 😀)Thank you to everyone who is part of this effort.
Europol announcement: https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks
#Trustandsafety #Endgame #SocGholish #Disruption #Infosec #CyberSecurity #Malware
-
📢 ENDGAME REMEDIATION - SOCGHOLISH | Following last week’s announcement and today’s update from Europol (link below), the disruption effort against SocGholish has expanded to include Amadey and StealC.
Spamhaus is now sending notification emails 📩 to hosters of confirmed compromised WordPress sites.
Here's what to do if you receive one:
👉 Go to this remediation webpage: https://www.spamhaus.org/endgame-socgholish
👉 Enter the access code included in the email
👉 Download the list of compromised WordPress administrator credentials
👉 Verify and where necessary, contact the owner to update their credentials, enable multi-factor authentication, remove any unrecognised WordPress accounts, and ensure your WordPress installation is fully up to date. (there's a ready-made email template for you to use on the remediation webpage 😀)Thank you to everyone who is part of this effort.
Europol announcement: https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks
#Trustandsafety #Endgame #SocGholish #Disruption #Infosec #CyberSecurity #Malware
-
🕵🏻♂️ [InfoSec MASHUP] 25/2026 - Client-Side Authorization Is Not Authorization
BobDaHacker didn't find a zero-day. She didn't exploit a memory corruption bug or chain together three CVEs. She uploaded a photo of her ID to FIFA's public agent registration portal, got added to FIFA's #Microsoft Entra tenant, and walked straight into the live production Streaming Management panel for the #FIFA World Cup 2026. Every match. Every camera angle. Every RTMP stream key. One click away from replacing the PGM feed — the main broadcast output going to every TV network worldwide — with whatever she felt like pushing. She did not push anything. She spent the rest of the night calling FIFA, MediaKind, HBS, CISA, and the FBI trying to get someone to pick up the phone.
The root cause is almost insultingly mundane: client-side authorization with no server-side enforcement. The Angular frontend checked the JWT, found no roles, showed an "access denied" page. The backend APIs didn't check anything. FIFA fixed it by the next morning without ever responding to the researcher. She's still on their official match document distribution list, receiving Start Lists and Tactical Lineups in four languages. The vulnerability is gone. The bug bounty program, the security.txt file, and the acknowledgment to the person who saved them from a global broadcast catastrophe remain absent. Client-side authorization is not authorization. It's 2026.
→ Week #25/2026 also covers: The #SocGholish botnet is down after nine years, Texas leaked 3M driver's licenses and passports, and dozens of cybersecurity vets are calling the #Anthropic ban dangerous
Full issue 👉 https://infosec-mashup.santolaria.net/p/infosec-mashup-25-2026-client-side-authorization-is-not-authorization
If you find it useful, subscribe to get it in your inbox every weekend 📨
-
Operation #Endgame putzt #SocGholish #Malware von #WordPress Blogs und schaltet Server ab.
https://borncity.com/blog/2026/06/20/operation-endgame-schaltet-socgholish-malware-infrastruktur-ab/
-
Fazit: Hätte man Updates zeitnah eingespielt, wäre die Wahrscheinlichkeit geringer gewesen kompromittiert zu werden.
#OperationEndgame: Ermittler säubern tausende Blogs von #SocGholish | Security https://www.heise.de/news/Operation-Endgame-Ermittler-saeubern-tausende-Blogs-von-SocGholish-11337399.html #malware
-
#Police cleans nearly 15,000 #SocGholish-infected sites tied to #EvilCorp
-
Operation Endgame abbatte SocGholish: 100 server offline e 15.000 siti risanati nell’operazione contro Evil Corp
Il 18 giugno 2026 un'operazione internazionale di law enforcement ha colpito TA569, il gruppo legato a Evil Corp che distribuisce SocGholish attraverso siti web compromessi. Oltre 100 server abbattuti, quasi 15.000 siti risanati. Ecco la ricostruzione tecnica completa. -
📣🚨 #OperationEndgame disrupts TA569’s SocGholish malware infrastructure, with law enforcement taking down 100+ C2 servers and cleaning 15,000 hacked sites.
Read: https://hackread.com/operation-endgame-disrupts-socgholish-malware/
#SocGholish #Malware #Cybersecurity #CyberCrime #Ransomware #TA569
-
🔥 Operation Endgame is back! This latest operation targets #SocGholish (FakeUpdates) malware, used by the notorious criminal group: Evil Corp. It's another major international effort that’s taken down 106 servers and domains, with 14,971 infected WordPress websites remediated.
Excellent work by all partners involved!! 👏 👏
🔧 REMEDIATION: As with previous phases of #OperationEndgame, Spamhaus is proud to support remediation efforts. Website owners affected by this operation will be contacted with guidance on the next steps.
➡️ Dutch National Police press release: https://www.politie.nl/en/news/2026/juni/18/11-international-law-enforcement-initiate-hunt-on-malware-group-socgholish.html
➡️ Operation Endgame: https://operation-endgame.com#CyberSecurity #ThreatIntelligence #SocGholish #FakeUpdates #Malware #EvilCorp #OperationEndgame
-
New season of #OperationEndgame just dropped.
This time, they targeted #SocGholish.
106 servers and domains taken down, 14.971 websites remediated.
Of course, they released a movie like video for it again.
Press release: https://www.politie.nl/en/news/2026/juni/18/11-international-law-enforcement-initiate-hunt-on-malware-group-socgholish.html
#OpEndgame #SocGholish -
Cyberattacks Against the US Intensify as Russian Groups Target Engineering Firm https://thecyberexpress.com/cyberattacks-against-the-us/ #CenterforCounteringDisinformation #cyberattacksagainsttheUS #TheCyberExpressNews #TheCyberExpress #FirewallDaily #SocGholish #CyberNews #RomCom
-
New RomCom campaign observed using SocGholish to deliver the Mythic Agent payload. Targets: U.S. organizations supporting Ukraine. Researchers also link the operation to GRU Unit 29155.
#infosec #ThreatIntel #RomCom #SocGholish #Malware #MythicAgent #GRU
-
Russian RomCom Utilizing SocGholish to Deliver Mythic Agent to U.S. Companies Supporting Ukraine
#RomComGroup #SocGholish #TA569
https://arcticwolf.com/resources/blog/romcom-utilizing-socgholish-to-deliver-mythic-agent-to-usa-companies-supporting-ukraine/ -
SocGholish Malware Using Compromised Sites to Deliver Ransomware https://hackread.com/socgholish-malware-compromised-sites-ransomware/ #Cybersecurity #CyberAttack #FakeUpdates #SocGholish #Security #Malware #TA569 #MaaS #RAT
-
Watch out as new research shows SocGholish Malware as Service (MaaS) is exploiting compromised websites and fake software updates to push ransomware and infostealers worldwide.
Read: https://hackread.com/socgholish-malware-compromised-sites-ransomware/
-
SocGholish Malware Spread via Ad Tools; Delivers Access to LockBit, Evil Corp, and Others – Source:thehackernews.com https://ciso2ciso.com/socgholish-malware-spread-via-ad-tools-delivers-access-to-lockbit-evil-corp-and-others-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #SocGholish
-
@filippo the copy/paste technique is called #ClickFix . the site in the image is infected by TA2726's Keitaro which is well known for sending Windows folks to #SocGholish . what they do with macOS folks has changed over the years. i see they sent you to something that delivered what looks like Poseidon Stealer.
https://medium.com/@MateoPappa/letsdefend-poseidon-macos-stealer-hard-a796c85d8c72
-
SocGholish: From loader and C2 activity to RansomHub deployment
#SocGholish #RansomHubRansomware
https://www.darktrace.com/blog/socgholish-from-loader-and-c2-activity-to-ransomhub-deployment -
We’re seeing an increasing volume of blocked queries to the SocGholish-related domain - blackshelter[.]org in the last several days.
-
Notorious Malware, Spam Host “Prospero” Moves to Kaspersky Lab
https://krebsonsecurity.com/2025/02/notorious-malware-spam-host-prospero-moves-to-kaspersky-lab/
#InterisleConsultingGroup #Ne'er-Do-WellNews #ALittleSunshine #TheComingStorm #KasperskyLab #ProsperoOOO #ZachEdwards #Ransomware #GootLoader #Securehost #SilentPush #SocGholish #Intrinsec #AlfaBank #BEARHOST #spamhaus #Kentik
-
Notorious Malware, Spam Host “Prospero” Moves to Kaspersky Lab https://krebsonsecurity.com/2025/02/notorious-malware-spam-host-prospero-moves-to-kaspersky-lab/ #InterisleConsultingGroup #Ne'er-Do-WellNews #ALittleSunshine #TheComingStorm #KasperskyLab #ProsperoOOO #ZachEdwards #Ransomware #GootLoader #Securehost #SilentPush #SocGholish #Intrinsec #AlfaBank #BEARHOST #spamhaus #Kentik