SocGholish, also widely tracked as FakeUpdates, is a long-running JavaScript-based malware delivery framework and loader used to obtain initial access through fake browser or software update lures. Active since at least 2017–2018, it is commonly deployed through compromised legitimate websites in drive-by-download and watering-hole operations, where injected scripts selectively redirect Windows users to fraudulent update pages. Victims are tricked into downloading and executing archive-contained JavaScript or HTA stages that profile the host, perform anti-analysis checks, and retrieve follow-on payloads.
SocGholish is strongly associated with financially motivated intrusion activity and has been linked in public reporting to Evil Corp and the Indrik Spider cluster. It has functioned as a major corporate initial access vector and has been observed delivering a range of secondary payloads including NetSupport RAT, Cobalt Strike, BLISTER, Dridex, Zloader-related tooling, and ransomware-enabling access that preceded WastedLocker, Hades, LockBit, and other post-compromise operations. Reporting also indicates it can be distributed through malvertising and poisoned search results in addition to compromised websites, and that access to its infrastructure may be shared with or sold to downstream criminal operators.
On execution, SocGholish commonly gathers extensive system and domain information, including host identity, user context, security products, processes, services, and Active Directory-related data. Subsequent stages have used PowerShell, command shells, tampered DLLs, in-memory execution, and process injection to deploy payloads and support hands-on-keyboard activity. Observed follow-on behavior includes reconnaissance, credential and browser-data collection, lateral movement preparation, persistence establishment, defense evasion, and large-scale staging for ransomware deployment. The framework is notable for selective victim filtering, evolving obfuscation, domain shadowing, and other evasive delivery techniques that complicate detection and analysis.
SocGholish primarily targets Microsoft Windows environments and is especially relevant to enterprise intrusions because it frequently serves as the bridge between web-based social engineering and full post-exploitation operations against organizations across sectors including education, government, healthcare, finance, manufacturing, legal services, transportation, and other corporate environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
And furthermore, this particular variation of injection was used by many massive website infection campaigns, including the attacks following the infamous Drupalgeddon 2. | This NDSW/NDSX malware — also referred to as FakeUpdates or SocGholish by other research groups — is responsible for redirecting site visitors to malicious pages designed to trick victims into loading and installing fake browser updates.
This occurred via the SocGholish JavaScript framework, found earlier this year on dozens of hacked newspaper sites owned by the same company.
CVE-2026-41940, the cPanel authentication bypass, illustrates the opportunistic mass-exploitation pattern most clearly. What began as exploratory probing evolved into a multi-actor campaign combining ransomware deployment, website defacement, and — in at least one documented case — targeted cyber-espionage. | We also now increasingly observe this vulnerability within attack chains of threat actors that rely on compromising legitimate websites via web inject, such as TA569 (SocGholish).
17 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Shady Squirrel ... sends traffic to initial access brokers and cybercriminals like SocGholish ... SocGholish is believed to have regained access to thousands of compromised sites by teaming up with the threat actor merely days after its infrastructure was disrupted in a law enforcement operation.
SocGholish is an advanced delivery framework used in drive-by-download and watering hole attacks... First seen in the wild in April 2018, SocGholish is a drive-by-download framework used in social engineering attacks to deliver a range of remote access trojans and ransom tools.
This NDSW/NDSX malware — also referred to as FakeUpdates or SocGholish by other research groups — is responsible for redirecting site visitors to malicious pages designed to trick victims into loading and installing fake browser updates.
The tech giant said it observed the FakeUpdates (aka SocGholish) malware being delivered via existing Raspberry Robin infections on July 26, 2022.
Recorded Future exploits TDS to demonstrate a high-level activity strategy that includes regularly updating URLs embedded in WordPress sites, adding additional servers, and improving TDS logic to evade detection, and has been linked to SocGholish and D3F@ck Loader malware, as well as the Rhysida and Interlock ransomware groups.
Active since 2017 and also known as FakeUpdates, SocGholish is a JavaScript (JS)-based downloader malware that typically serves as a conduit for next-stage malware from various threat actors like Evil Corp, LockBit, RansomHub, Dridex, and Raspberry Robin.
26 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure.
they acquire expired domains that were previously compromised by other attackers and simply inherit the existing infection traffic.
SocGholish JavaScript framework loader components that profile the victim system and use PowerShell to ultimately deploy Cobalt Strike payloads
this allows the malware to proceed with connecting to its command-and-control (C&C) domain and deploy several discovery commands to gather information regarding the system.
If you use Google Chrome, the fake browser page sends an HTA file instead of a zip archive.
The downloaded zip archive contained a JavaScript file with heavily obfuscated Javascript... the fake Firefox update page sent a zip archive containing a file named Firefox.js for the malware downloader.
The injected code is highly-obfuscated... The downloaded zip archive contained a JavaScript file with heavily obfuscated Javascript... This NetSupport RAT-based malware package was sent as a 10MB ASCII text file consisting of hexadecimal characters. This is encoded data, and the file was saved to my lab host and decoded to a zip archive containing the malware package.
Fake browser update pages... If you use Google Chrome, the fake browser page sends an HTA file instead of a zip archive. In my example, the fake Firefox update page sent a zip archive containing a file named Firefox.js for the malware downloader.
rather than buying domains wholesale for a planned operation, they acquire expired domains that were previously compromised by other attackers and simply inherit the existing infection traffic.
Also, this .js-based downloader (or HTA-based downloader if you had a fake Chrome update page) is extremely VM-aware.
"C:\Windows\System32\cmd.exe" /C whoami /all >> "C:\Users\victim\AppData\Local\Temp\rad95E90.tmp"
The bot collects a large set of information and sends that to the SocGholish server side which, in turn, returns a payload to the victim system.
"C:\Windows\System32\cmd.exe" /C net group "domain admins" /domain ... "C:\Windows\System32\cmd.exe" /C net user victim /domain
"C:\Windows\System32\cmd.exe" /C nltest /domain_trusts ... "C:\Windows\System32\cmd.exe" /C nltest /dclist:
Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure.
opère un TDS (Traffic Distribution System)... Monétisation via réseaux publicitaires affiliés : PushHouse, ExoClick... Utilise... Keitaro TDS
263 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
195 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware framework associated here with compromised websites and downstream delivery via dropcaught malicious domains.
Malware receiving inherited infection traffic from expired malicious domains acquired by Shady Squirrel.
Malware traffic recipient associated with scavenged expired malicious domains.
Fake-update malware infrastructure used to deliver malware via scareware and call-center lures.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.