SocGholish, also known as FakeUpdates, is a JavaScript-based malware loader and distribution framework targeting Microsoft Windows. It provides initial access for financially motivated intrusions by delivering additional malware and enabling subsequent hands-on-keyboard activity. Its principal distribution mechanism is compromised websites that display fraudulent browser or software-update prompts. Victims are induced to download and execute malicious JavaScript, sometimes packaged in archives. SocGholish has also been distributed through phishing and watering-hole campaigns.
The initial payload executes through Windows Script Host, establishes command-and-control communications, and profiles the compromised environment. Discovery includes checking domain membership and enumerating system information, users, privileged groups, domain controllers, domain trusts, processes, services, and installed security products. Results are staged locally and transmitted to attacker-controlled infrastructure. Infection chains use legitimate Windows utilities, PowerShell, and obfuscated scripts, with scheduled tasks providing persistence in observed campaigns. Some chains install an embedded Python runtime to execute persistent follow-on code.
SocGholish has delivered Cobalt Strike, AsyncRAT, maliciously configured installations of the legitimate BOINC distributed-computing platform, and MintsLoader. SocGholish-origin intrusions have also led to ransomware deployment, including LockBit and WastedLocker; downstream credential theft and lateral movement are performed by follow-on payloads or operators rather than necessarily by the JavaScript loader itself. Its ecosystem has been associated with Evil Corp and the initial access broker Exotic Lily, and SocGholish operators are tracked as TA569. Frequently affected sectors include accommodation and food services, retail, and legal services, particularly in the United States.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
And furthermore, this particular variation of injection was used by many massive website infection campaigns, including the attacks following the infamous Drupalgeddon 2. | This NDSW/NDSX malware — also referred to as FakeUpdates or SocGholish by other research groups — is responsible for redirecting site visitors to malicious pages designed to trick victims into loading and installing fake browser updates.
This occurred via the SocGholish JavaScript framework, found earlier this year on dozens of hacked newspaper sites owned by the same company.
CVE-2026-41940, the cPanel authentication bypass, illustrates the opportunistic mass-exploitation pattern most clearly. What began as exploratory probing evolved into a multi-actor campaign combining ransomware deployment, website defacement, and — in at least one documented case — targeted cyber-espionage. | We also now increasingly observe this vulnerability within attack chains of threat actors that rely on compromising legitimate websites via web inject, such as TA569 (SocGholish).
19 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The infamous SocGholish (aka FakeUpdates) is a JavaScript-based loader that targets Microsoft Windows-based environments.
Initial access was achieved through a SocGholish infection. Following this, Cobalt Strike was loaded onto the host and command-and-control (C2) established.
The “SocGholish” (aka FakeUpdates) malware distribution framework ... Just in January, we’ve identified and responded to two discrete “hands-on-keyboard” intrusions traced back to a SocGholish compromise.
The SocGholish malware often poses as a browser update. When users visit sites that have been compromised, they are prompted to install the update.
The review covers a SocGholish (FakeUpdates) intrusion initiated when a user visited a compromised WordPress site and executed Update.js delivered through a fake browser-update prompt.
Shady Squirrel ... sends traffic to initial access brokers and cybercriminals like SocGholish ... SocGholish is believed to have regained access to thousands of compromised sites by teaming up with the threat actor merely days after its infrastructure was disrupted in a law enforcement operation.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
285 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
200 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Microsoft had previously dismantled cybercrime-as-a-service infrastructure belonging to gangs distributing SocGholish, Amadey and StealC malware.
Malware framework associated here with compromised websites and downstream delivery via dropcaught malicious domains.
Malware receiving inherited infection traffic from expired malicious domains acquired by Shady Squirrel.
Malware traffic recipient associated with scavenged expired malicious domains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.