started · updated
Russian Evil Corp linked to global fake update scam in multinational police operation
Canadian police announced a coordinated takedown of a worldwide fake‑update scheme that used the SocGholish malware linked to the Russian cybercriminal group Evil Corp. The operation, called “Operation Endgame,” involved the Royal Canadian Mounted Police working with law‑enforcement agencies in the Netherlands, the United States and Germany. Together the partners shut down 106 servers and domains, remediated almost 15,000 compromised WordPress sites and warned site owners to change credentials and enable multi‑factor authentication.
Authorities urged the public to avoid pop‑up windows or flashy update prompts that request immediate action, as these are typical vectors for the malicious files. The campaign targeted thousands of users by disguising malware as legitimate computer updates.
The joint effort demonstrates increased international cooperation against cybercrime that exploits vulnerable content‑management systems worldwide.