FakeSG is a malware delivery campaign centered on fake browser-update lures delivered through compromised websites, primarily hacked WordPress installations. It has been identified as a distinct fake-update operation that resembles the broader FakeUpdates/SocGholish ecosystem in user-facing tradecraft but differs in template code, obfuscation, and delivery infrastructure. The campaign uses injected JavaScript on compromised sites to replace legitimate page content with convincing browser-specific update prompts designed to induce user execution. Observed FakeSG infection chains deliver NetSupport RAT either through archive downloads or through Internet shortcut files that retrieve an obfuscated HTA payload over WebDAV. The HTA then executes PowerShell to download and launch the final remote-access payload. Reported behavior includes command execution, obfuscated scripting, use of system binary proxy execution, registry modification, and UAC-bypass-related activity, indicating a multi-stage intrusion flow with strong emphasis on defense evasion and post-compromise control. FakeSG has been discussed alongside related fake-update activity, including overlap in general technique with FakeUpdates, also known as SocGholish, and similarities to activity referred to as RogueRaticate. However, it is treated as a separate campaign rather than a confirmed alias of those operations. Based on observed delivery of NetSupport RAT and the mapped ATT&CK behaviors, FakeSG demonstrates initial-access, defense-evasion, persistence-enabling, and post-exploitation capability. Publicly available information does not support a high-confidence attribution to a specific country or state sponsor.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.