started · updated
Operation Endgame dismantles SocGholish botnet, seizes 106 servers, cleans 15,000 WordPress sites
International law‑enforcement agencies from the Netherlands, Canada, the United States and Germany, supported by Europol and Eurojust, carried out Operation Endgame against the SocGholish malware network. The coordinated raid seized 106 servers and domains used to control the botnet and removed malicious code from 14,971 WordPress sites that had been infected with fake‑update payloads.
SocGholish, also known as FakeUpdates or GhoLoader, is attributed to the Russian cyber‑crime group Evil Corp and has been used as an initial‑access broker for ransomware and banking‑trojan families. The operation highlights evolving attack techniques such as MFA‑bypass tokens and comes as Canada and the EU tighten reporting and cooperation requirements for cyber incidents. Authorities advised site owners to change passwords, enable multi‑factor authentication, delete unknown CMS accounts and fully update software.