home.social

#socgholish — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #socgholish, aggregated by home.social.

fetched live
  1. Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

    Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.

    Pulse ID: 6a7ec3107e8b34f88b5d610e
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: AlienVault
    Created: 2026-08-14 07:26:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault

  2. Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

    Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.

    Pulse ID: 6a7ec3107e8b34f88b5d610e
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: AlienVault
    Created: 2026-08-14 07:26:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault

  3. Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

    Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.

    Pulse ID: 6a7ec3107e8b34f88b5d610e
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: AlienVault
    Created: 2026-08-14 07:26:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault

  4. Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

    Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.

    Pulse ID: 6a7ec3107e8b34f88b5d610e
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: AlienVault
    Created: 2026-08-14 07:26:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault

  5. Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows

    Three financially motivated threat actors acquire expired malicious domains through dropcatch to inherit traffic from previously compromised websites. Stuffy Squirrel specializes in hiding activity within legitimate scripts and has operated since 2020, selling traffic to affiliate advertising networks. Shady Squirrel uses custom JavaScript and Keitaro injections with multi-step cloaking, partnering with initial access brokers to deliver tech support scams and SocGholish malware, notably facilitating SocGholish's return within weeks of Operation Endgame disruption. Swiping Squirrel, the most prolific actor, operates in greyhat territory by selling fraudulent traffic to zero-click advertising platforms like ZeroPark, often resulting in malvertising and malware distribution. These actors control thousands of domains collectively, exploiting lingering infections from previous compromises without conducting new attacks themselves.

    Pulse ID: 6a7ec3107e8b34f88b5d610e
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: AlienVault
    Created: 2026-08-14 07:26:08

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Java #JavaScript #Malvertising #Malware #OTX #OpenThreatExchange #RAT #SocGholish #Squirrel #bot #AlienVault

  6. Not the right person to action this yourself? ➡️ Forward this to whoever handles abuse reports or security escalations at your company.

    It takes less than 5 minutes to pull the list and get started 🙏

    #Trustandsafety #SocGholish #Remediation

    3/3

  7. Not the right person to action this yourself? ➡️ Forward this to whoever handles abuse reports or security escalations at your company.

    It takes less than 5 minutes to pull the list and get started 🙏

    #Trustandsafety #SocGholish #Remediation

    3/3

  8. Not the right person to action this yourself? ➡️ Forward this to whoever handles abuse reports or security escalations at your company.

    It takes less than 5 minutes to pull the list and get started 🙏

    #Trustandsafety #SocGholish #Remediation

    3/3

  9. Not the right person to action this yourself? ➡️ Forward this to whoever handles abuse reports or security escalations at your company.

    It takes less than 5 minutes to pull the list and get started 🙏

    #Trustandsafety #SocGholish #Remediation

    3/3

  10. Not the right person to action this yourself? ➡️ Forward this to whoever handles abuse reports or security escalations at your company.

    It takes less than 5 minutes to pull the list and get started 🙏

    #Trustandsafety #SocGholish #Remediation

    3/3

  11. 📢 ENDGAME REMEDIATION - SOCGHOLISH | Following last week’s announcement and today’s update from Europol (link below), the disruption effort against SocGholish has expanded to include Amadey and StealC.

    Spamhaus is now sending notification emails 📩 to hosters of confirmed compromised WordPress sites.

    Here's what to do if you receive one:

    👉 Go to this remediation webpage: spamhaus.org/endgame-socgholish
    👉 Enter the access code included in the email
    👉 Download the list of compromised WordPress administrator credentials
    👉 Verify and where necessary, contact the owner to update their credentials, enable multi-factor authentication, remove any unrecognised WordPress accounts, and ensure your WordPress installation is fully up to date. (there's a ready-made email template for you to use on the remediation webpage 😀)

    Thank you to everyone who is part of this effort.

    Europol announcement: europol.europa.eu/media-press/

    #Trustandsafety #Endgame #SocGholish #Disruption #Infosec #CyberSecurity #Malware

  12. 📢 ENDGAME REMEDIATION - SOCGHOLISH | Following last week’s announcement and today’s update from Europol (link below), the disruption effort against SocGholish has expanded to include Amadey and StealC.

    Spamhaus is now sending notification emails 📩 to hosters of confirmed compromised WordPress sites.

    Here's what to do if you receive one:

    👉 Go to this remediation webpage: spamhaus.org/endgame-socgholish
    👉 Enter the access code included in the email
    👉 Download the list of compromised WordPress administrator credentials
    👉 Verify and where necessary, contact the owner to update their credentials, enable multi-factor authentication, remove any unrecognised WordPress accounts, and ensure your WordPress installation is fully up to date. (there's a ready-made email template for you to use on the remediation webpage 😀)

    Thank you to everyone who is part of this effort.

    Europol announcement: europol.europa.eu/media-press/

    #Trustandsafety #Endgame #SocGholish #Disruption #Infosec #CyberSecurity #Malware

  13. 🕵🏻‍♂️ [InfoSec MASHUP] 25/2026 - Client-Side Authorization Is Not Authorization

    BobDaHacker didn't find a zero-day. She didn't exploit a memory corruption bug or chain together three CVEs. She uploaded a photo of her ID to FIFA's public agent registration portal, got added to FIFA's #Microsoft Entra tenant, and walked straight into the live production Streaming Management panel for the #FIFA World Cup 2026. Every match. Every camera angle. Every RTMP stream key. One click away from replacing the PGM feed — the main broadcast output going to every TV network worldwide — with whatever she felt like pushing. She did not push anything. She spent the rest of the night calling FIFA, MediaKind, HBS, CISA, and the FBI trying to get someone to pick up the phone.

    The root cause is almost insultingly mundane: client-side authorization with no server-side enforcement. The Angular frontend checked the JWT, found no roles, showed an "access denied" page. The backend APIs didn't check anything. FIFA fixed it by the next morning without ever responding to the researcher. She's still on their official match document distribution list, receiving Start Lists and Tactical Lineups in four languages. The vulnerability is gone. The bug bounty program, the security.txt file, and the acknowledgment to the person who saved them from a global broadcast catastrophe remain absent. Client-side authorization is not authorization. It's 2026.

    → Week #25/2026 also covers: The #SocGholish botnet is down after nine years, Texas leaked 3M driver's licenses and passports, and dozens of cybersecurity vets are calling the #Anthropic ban dangerous

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨

    #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  14. 🕵🏻‍♂️ [InfoSec MASHUP] 25/2026 - Client-Side Authorization Is Not Authorization

    BobDaHacker didn't find a zero-day. She didn't exploit a memory corruption bug or chain together three CVEs. She uploaded a photo of her ID to FIFA's public agent registration portal, got added to FIFA's #Microsoft Entra tenant, and walked straight into the live production Streaming Management panel for the #FIFA World Cup 2026. Every match. Every camera angle. Every RTMP stream key. One click away from replacing the PGM feed — the main broadcast output going to every TV network worldwide — with whatever she felt like pushing. She did not push anything. She spent the rest of the night calling FIFA, MediaKind, HBS, CISA, and the FBI trying to get someone to pick up the phone.

    The root cause is almost insultingly mundane: client-side authorization with no server-side enforcement. The Angular frontend checked the JWT, found no roles, showed an "access denied" page. The backend APIs didn't check anything. FIFA fixed it by the next morning without ever responding to the researcher. She's still on their official match document distribution list, receiving Start Lists and Tactical Lineups in four languages. The vulnerability is gone. The bug bounty program, the security.txt file, and the acknowledgment to the person who saved them from a global broadcast catastrophe remain absent. Client-side authorization is not authorization. It's 2026.

    → Week #25/2026 also covers: The #SocGholish botnet is down after nine years, Texas leaked 3M driver's licenses and passports, and dozens of cybersecurity vets are calling the #Anthropic ban dangerous

    Full issue 👉 infosec-mashup.santolaria.net/

    If you find it useful, subscribe to get it in your inbox every weekend 📨

    #infosecMASHUP #cybersecurity #infosec #threatintel #AI

  15. Cyber Journaal S02E73, het Ministerie van Financiën gehackt via een zeroday, de politie rolt het SocGholish netwerk op en bijna 74.000 Fortinet firewalls liggen op straat. ccinfo.nl/journaal/3235079_fin #Cybersecurity #SocGholish #FortiBleed

  16. Fazit: Hätte man Updates zeitnah eingespielt, wäre die Wahrscheinlichkeit geringer gewesen kompromittiert zu werden.

    #OperationEndgame: Ermittler säubern tausende Blogs von #SocGholish | Security heise.de/news/Operation-Endgam #malware

  17. Fazit: Hätte man Updates zeitnah eingespielt, wäre die Wahrscheinlichkeit geringer gewesen kompromittiert zu werden.

    #OperationEndgame: Ermittler säubern tausende Blogs von #SocGholish | Security heise.de/news/Operation-Endgam #malware

  18. Operation Endgame abbatte SocGholish: 100 server offline e 15.000 siti risanati nell’operazione contro Evil Corp

    Il 18 giugno 2026 un'operazione internazionale di law enforcement ha colpito TA569, il gruppo legato a Evil Corp che distribuisce SocGholish attraverso siti web compromessi. Oltre 100 server abbattuti, quasi 15.000 siti risanati. Ecco la ricostruzione tecnica completa.

    insicurezzadigitale.com/operat

  19. Operation Endgame abbatte SocGholish: 100 server offline e 15.000 siti risanati nell’operazione contro Evil Corp

    Il 18 giugno 2026 un'operazione internazionale di law enforcement ha colpito TA569, il gruppo legato a Evil Corp che distribuisce SocGholish attraverso siti web compromessi. Oltre 100 server abbattuti, quasi 15.000 siti risanati. Ecco la ricostruzione tecnica completa.

    insicurezzadigitale.com/operat

  20. 📣🚨 disrupts TA569’s SocGholish malware infrastructure, with law enforcement taking down 100+ C2 servers and cleaning 15,000 hacked sites.

    Read: hackread.com/operation-endgame

  21. 🔥 Operation Endgame is back! This latest operation targets #SocGholish (FakeUpdates) malware, used by the notorious criminal group: Evil Corp. It's another major international effort that’s taken down 106 servers and domains, with 14,971 infected WordPress websites remediated.

    Excellent work by all partners involved!! 👏 👏

    🔧 REMEDIATION: As with previous phases of #OperationEndgame, Spamhaus is proud to support remediation efforts. Website owners affected by this operation will be contacted with guidance on the next steps.

    ➡️ Dutch National Police press release: politie.nl/en/news/2026/juni/1
    ➡️ Operation Endgame: operation-endgame.com

    #CyberSecurity #ThreatIntelligence #SocGholish #FakeUpdates #Malware #EvilCorp #OperationEndgame

  22. 🔥 Operation Endgame is back! This latest operation targets #SocGholish (FakeUpdates) malware, used by the notorious criminal group: Evil Corp. It's another major international effort that’s taken down 106 servers and domains, with 14,971 infected WordPress websites remediated.

    Excellent work by all partners involved!! 👏 👏

    🔧 REMEDIATION: As with previous phases of #OperationEndgame, Spamhaus is proud to support remediation efforts. Website owners affected by this operation will be contacted with guidance on the next steps.

    ➡️ Dutch National Police press release: politie.nl/en/news/2026/juni/1
    ➡️ Operation Endgame: operation-endgame.com

    #CyberSecurity #ThreatIntelligence #SocGholish #FakeUpdates #Malware #EvilCorp #OperationEndgame

  23. New season of #OperationEndgame just dropped.
    This time, they targeted #SocGholish.
    106 servers and domains taken down, 14.971 websites remediated.
    Of course, they released a movie like video for it again.
    Press release: politie.nl/en/news/2026/juni/1
    #OpEndgame #SocGholish

  24. New season of #OperationEndgame just dropped.
    This time, they targeted #SocGholish.
    106 servers and domains taken down, 14.971 websites remediated.
    Of course, they released a movie like video for it again.
    Press release: politie.nl/en/news/2026/juni/1
    #OpEndgame #SocGholish

  25. Watch out as new research shows SocGholish Malware as Service (MaaS) is exploiting compromised websites and fake software updates to push ransomware and infostealers worldwide.

    Read: hackread.com/socgholish-malwar

  26. Watch out as new research shows SocGholish Malware as Service (MaaS) is exploiting compromised websites and fake software updates to push ransomware and infostealers worldwide.

    Read: hackread.com/socgholish-malwar

    #SocGholish #Malware #FakeUpdates #Ransomware #InfoStealer

  27. @filippo the copy/paste technique is called #ClickFix . the site in the image is infected by TA2726's Keitaro which is well known for sending Windows folks to #SocGholish . what they do with macOS folks has changed over the years. i see they sent you to something that delivered what looks like Poseidon Stealer.

    medium.com/@MateoPappa/letsdef

  28. @filippo the copy/paste technique is called #ClickFix . the site in the image is infected by TA2726's Keitaro which is well known for sending Windows folks to #SocGholish . what they do with macOS folks has changed over the years. i see they sent you to something that delivered what looks like Poseidon Stealer.

    medium.com/@MateoPappa/letsdef

  29. We’re seeing an increasing volume of blocked queries to the SocGholish-related domain - blackshelter[.]org in the last several days.

    #DNS #SocGholish #ransomware #malware #infosec