Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

    September 12, 2026

    Aging Congress Is Completely Ill-Equipped to Regulate AI, or Seemingly Even Understand It

    September 12, 2026

    Samsung Galaxy S26 FE’s India price leaks

    September 12, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown 
    15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown 
    Cybersecurity

    15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown 

    The Tech GuyBy The Tech GuyJune 20, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Law enforcement agencies in four countries, working with Europol and private partners, have disrupted SocGholish infrastructure and cleaned up nearly 15,000 infected WordPress websites.

    Advertisement

    Active since 2017 and also known as FakeUpdates, SocGholish is a malware framework injected into websites running popular content management systems, such as WordPress, Joomla, and Drupal, either via known vulnerabilities or stolen credentials.

    The framework acts as a JavaScript-based dropper, deploying various malware families as part of drive-by downloads, including ransomware, banking trojans, spyware, and more, and has been one of the most used loaders for years.

    SocGholish is operated by a Russian-speaking threat actor tracked as DEV-0206, Gold Prelude, Mustard Tempest, TA569, and UNC1543, which acts as an initial access broker and has been associated with the infamous Evil Corp gang (believed to be linked to Russian intelligence).

    TA569 has been observed indiscriminately compromising websites to inject the SocGholish loader, including prominent media and retail portals visited by millions of users daily.

    The malware profiles a victim’s browser, performs specific checks, and then overwrites the entire webpage with a fake browser update to entice the user into downloading a malicious payload, Proofpoint explains.

    Advertisement. Scroll to continue reading.

    Orange’s cyber defense unit observed SocGholish delivering loaders like Gholoader and MintsLoader, which eventually led to payloads such as the GhostWeaver PowerShell backdoor, LockBit and RansomHub ransomware, and AsyncRAT or NetSupport RAT backdoors.

    According to Infoblox, approximately 55% of cloud customers were exposed to SocGholish this year, which demonstrates the high risk the botnet poses to enterprises worldwide.

    The ShadowServer Foundation puts that into better perspective: in May, there were more than 1.44 million compromised WordPress websites available for use by SocGholish.

    Authorities in the Netherlands, Canada, the US, and Germany, with support from Europol, took down 106 command-and-control (C&C) servers and domains associated with SocGholish, and removed backdoors and malware from 14.971 infected WordPress websites.

    The Dutch police say notifications were also sent to WordPress site owners whose compromised credentials were identified, urging them to change their logins, enable MFA, delete suspect accounts, and keep their sites updated.

    Related: Dutch Police Dismantle Massive 17-Million-Device Botnet

    Related: GlassWorm Botnet Disrupted

    Related: Tycoon 2FA Fully Operational Despite Law Enforcement Takedown

    Related: SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

    September 12, 2026

    BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

    September 12, 2026

    GitLab Vulnerability Exploited One Day After Disclosure

    September 12, 2026

    Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

    September 12, 2026

    Phishing Research Challenges Conventional Security Awareness Testing

    September 11, 2026

    In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

    September 12, 2026

    Aging Congress Is Completely Ill-Equipped to Regulate AI, or Seemingly Even Understand It

    September 12, 2026

    Samsung Galaxy S26 FE’s India price leaks

    September 12, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.