Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
loader-delivery-mechanismcybercrime-service-ecosystemthreat-infrastructure-trackinginitial-access-method

Operation Endgame Disrupts SocGholish Malware Delivery Network

Updated 2d agoFirst seen Jun 18, 20262 sources

An Operation Endgame action disrupted the SocGholish malware ecosystem by remediating 14,971 compromised websites and dismantling associated command-and-control infrastructure, according to Orange Cyberdefense. SocGholish, a JavaScript-based downloader linked to the Russian-speaking initial access broker TA569 and also tracked as UNC1543, Mustard Tempest, and GOLD PRELUDE, has compromised legitimate websites since at least 2017 and used fake browser update prompts to infect visitors. The malware has frequently served as an entry point for follow-on payloads including Gholoader, MintsLoader, GhostWeaver, AsyncRAT, NetSupport RAT, and ransomware operations such as LockBit and RansomHub.

The disruption targeted a broader cybercrime chain tied to traffic distribution services such as TA2726, with reporting also noting copycat activity from TA2727 distributing Lumma and DeerStealer, as well as links into the wider financially motivated ecosystem around Evil Corp. Defenders were warned that TA569 is likely to rebuild because SocGholish infrastructure rotates rapidly, often every 2 to 5 days, making continued monitoring essential. Recommended mitigations included patching internet-facing CMS platforms, strengthening credentials, enabling MFA, and training users to distrust unsolicited browser update pop-ups that are commonly used as infection lures.

Share:
Operation Endgame Disrupts SocGholish Malware Delivery Network
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jun 18, 20264d ago

Operation Endgame disrupts SocGholish infrastructure

On 2026-06-18, an Operation Endgame action significantly disrupted SocGholish by remediating 14,971 compromised websites and dismantling related command-and-control servers. Orange Cyberdefense described the move as a major strike against the malware ecosystem tied to TA569.

Operation Endgame strikes SocGholish | Orange Cyberdefense

Shield-6G project launches with 19 organizations

Dark Reading reported that 19 organizations joined the EU-funded Shield-6G project to develop cybersecurity capabilities for future 6G mobile networks. The project aims to build a cyber threat intelligence platform for operators and test defenses such as honeypots, AI-driven detection, digital twins, federated learning, and explainable AI.

EU Gets a Head Start in Developing 6G Network Security

SocGholish activity begins

Orange Cyberdefense said the SocGholish malware operation has been active since at least 2017, operating as a JavaScript-based downloader used by the threat actor tracked as TA569 and others. It has commonly been used as an initial access vector for follow-on malware and ransomware infections.

Operation Endgame strikes SocGholish | Orange Cyberdefense
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

48 LINKEDOpen in app
Threat actors
3 linked
Affected products
2 linked
Microsoft 365 CopilotCortex Xsiam
Organizations
35 linked
Microsoft CorporationMozillaSpotifyInstructureOrange CyberdefensePalo Alto NetworksFinancial TimesNetflixWordpressDark ReadingKaseyaIvantiSensepostAppleArupForbesDrupalJoomlaGoogleGetty ImagesCNBCThreatpostPenguin Random HouseMBP Network TechnologyInzpireArriva TrainsArkemaDimence GroupEDAGIkazia HospitalZiekenhuis Oost-LimburgVlerick Business SchoolSana CommerceBlanc & FischerSchiphol Telematics
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.