SocGholish is a long-running, Russian-speaking cybercrime operation and initial access broker active since at least 2017. It is widely tracked under aliases including FakeUpdates, TA569, DEV-0206, GOLD PRELUDE, Mustard Tempest, and UNC1543. The group is known for compromising legitimate websites—especially WordPress sites—and using injected JavaScript and traffic distribution systems to selectively present fake browser or software update lures to visitors. Victims who execute the downloaded payloads are profiled and handed into multi-stage malware delivery chains that provide the operators and their partners with footholds in enterprise environments. SocGholish primarily monetizes access by enabling downstream criminal activity. Reporting has repeatedly linked the operation to Evil Corp and to follow-on ransomware and intrusion activity involving families and loaders such as Cobalt Strike, BLISTER, GhoLoader, MintsLoader, NetSupport RAT, AsyncRAT, GhostWeaver, LockBit, RansomHub, RomCom-related payloads, and other post-compromise tooling. The actor has also been observed in ecosystems involving Raspberry Robin, where existing infections were used to distribute FakeUpdates and support later pre-ransomware behavior. Tradecraft centers on web compromise, malicious JavaScript injection, traffic filtering, victim fingerprinting, and staged payload delivery. SocGholish commonly performs host reconnaissance before delivering later stages, including collection of operating system, domain, user, security product, process, and hardware information. Observed intrusion chains include PowerShell-based loaders, JavaScript downloaders, scheduled-task or autorun persistence, DLL-based loaders, and in-memory execution of follow-on payloads. Associated activity has also included defense evasion through obfuscation, delayed execution, renamed legitimate binaries, selective delivery based on browser and environment checks, and use of compromised or shadowed web infrastructure. The operation has compromised websites across virtually every industry and has functioned as a major corporate initial access vector. Public reporting links it to broad exposure across public-sector and commercial environments worldwide, with especially large abuse of compromised WordPress infrastructure. In June 2026, Operation Endgame disrupted part of the SocGholish ecosystem by remediating nearly 15,000 compromised websites and dismantling supporting infrastructure, but subsequent reporting indicated the actor rapidly regained traffic through partnerships and affiliated traffic suppliers.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
25 malware families attributed to this actor across reporting.
20 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
CVE-2026-41940, the cPanel authentication bypass, illustrates the opportunistic mass-exploitation pattern most clearly. What began as exploratory probing evolved into a multi-actor campaign combining ransomware deployment, website defacement, and — in at least one documented case — targeted cyber-espionage.
480 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named cybercriminal actor/framework referenced as both a prior website-compromising actor and a downstream recipient of traffic redirected by Shady Squirrel.
A cybercriminal operation that benefited from traffic supplied by Shady Squirrel after disruption of its infrastructure.
Operator of SocGholish infrastructure that partnered with Shady Squirrel.
Fake update malware actor receiving traffic from Shady Squirrel via custom injections after disruption by Operation Endgame, allowing rapid re-access to compromised websites.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.