Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
cybercrime-service-ecosystemloader-delivery-mechanismransomware-group-operationcredential-stealer-activity

SocGholish Malware-as-a-Service Platform Distributes Ransomware via Weaponized Software Updates

Updated 3mo agoFirst seen Oct 23, 20252 sources

The SocGholish malware-as-a-service (MaaS) platform, also known as FakeUpdates, has been leveraged by threat group TA569 to distribute ransomware and information-stealing malware through weaponized software updates. Attackers compromise legitimate websites, particularly vulnerable WordPress sites, and use techniques such as domain shadowing to create malicious subdomains on trusted domains. These compromised sites are then used to deliver fake software updates, tricking users into downloading malware payloads including RansomHub and LockBit ransomware, AsyncRAT, and various infostealers.

SocGholish acts as an initial access broker, selling access to its infection methods to other criminal groups, including Evil Corp and Russian state-backed actors. Recent campaigns have involved distributing RansomHub ransomware via malicious Google Ads impersonating the HR portal of Kaiser Permanente, resulting in significant breaches at organizations such as Rite Aid and Change Healthcare. The platform's ability to facilitate a range of payloads and its use by multiple threat actors underscore its ongoing threat to organizations worldwide.

Share:
SocGholish Malware-as-a-Service Platform Distributes Ransomware via Weaponized Software Updates
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

1 event from the most recent confirmed update back to the earliest known activity.

1 EVENTS
Oct 22, 20258mo ago

Reports describe SocGholish using compromised sites to deliver ransomware

Security reporting in late October 2025 described SocGholish malware being distributed through compromised websites and weaponized fake software updates, with ransomware delivery highlighted as the end stage of the intrusion chain. The references provided do not include earlier dated milestones, victim disclosures, or a named patch or law-enforcement action.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.