SocGholish, also known as FakeUpdates, is a Windows-focused JavaScript malware delivery framework and initial-access service active since at least 2017–2018. It compromises legitimate websites, including WordPress sites accessed using stolen administrator credentials, and injects scripts that selectively redirect visitors to fraudulent browser or software-update pages. Victims are socially engineered to download and execute archives, JavaScript, or HTA content masquerading as updates. The loader profiles hosts, collects system and security-product information, performs anti-analysis checks, and uses Windows command interpreters or PowerShell to retrieve and launch follow-on payloads. SocGholish has delivered Cobalt Strike, NetSupport RAT, Dridex, banking malware, information stealers, and ransomware-enabling tooling, and has been used as a precursor to targeted ransomware incidents involving WastedLocker and LockBit. It is widely associated with the Indrik Spider/Evil Corp cybercriminal ecosystem, although delivery and access-broker partnerships can involve other actors. Campaigns use compromised websites, drive-by downloads, watering-hole activity, malicious advertising, and occasionally spam links to compromised sites; targeting commonly prioritizes first-time Windows visitors arriving through search engines or other third-party referrers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
And furthermore, this particular variation of injection was used by many massive website infection campaigns, including the attacks following the infamous Drupalgeddon 2. | This NDSW/NDSX malware — also referred to as FakeUpdates or SocGholish by other research groups — is responsible for redirecting site visitors to malicious pages designed to trick victims into loading and installing fake browser updates.
This occurred via the SocGholish JavaScript framework, found earlier this year on dozens of hacked newspaper sites owned by the same company.
CVE-2026-41940, the cPanel authentication bypass, illustrates the opportunistic mass-exploitation pattern most clearly. What began as exploratory probing evolved into a multi-actor campaign combining ransomware deployment, website defacement, and — in at least one documented case — targeted cyber-espionage. | We also now increasingly observe this vulnerability within attack chains of threat actors that rely on compromising legitimate websites via web inject, such as TA569 (SocGholish).
17 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Shady Squirrel ... sends traffic to initial access brokers and cybercriminals like SocGholish ... SocGholish is believed to have regained access to thousands of compromised sites by teaming up with the threat actor merely days after its infrastructure was disrupted in a law enforcement operation.
SocGholish is an advanced delivery framework used in drive-by-download and watering hole attacks... First seen in the wild in April 2018, SocGholish is a drive-by-download framework used in social engineering attacks to deliver a range of remote access trojans and ransom tools.
This NDSW/NDSX malware — also referred to as FakeUpdates or SocGholish by other research groups — is responsible for redirecting site visitors to malicious pages designed to trick victims into loading and installing fake browser updates.
The tech giant said it observed the FakeUpdates (aka SocGholish) malware being delivered via existing Raspberry Robin infections on July 26, 2022.
Recorded Future exploits TDS to demonstrate a high-level activity strategy that includes regularly updating URLs embedded in WordPress sites, adding additional servers, and improving TDS logic to evade detection, and has been linked to SocGholish and D3F@ck Loader malware, as well as the Rhysida and Interlock ransomware groups.
Active since 2017 and also known as FakeUpdates, SocGholish is a JavaScript (JS)-based downloader malware that typically serves as a conduit for next-stage malware from various threat actors like Evil Corp, LockBit, RansomHub, Dridex, and Raspberry Robin.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure.
Use Windows Attack Surface Reduction rules to block JavaScript and VBScript from launching downloaded content
SocGholish JavaScript framework loader components that profile the victim system and use PowerShell to ultimately deploy Cobalt Strike payloads
this allows the malware to proceed with connecting to its command-and-control (C&C) domain and deploy several discovery commands to gather information regarding the system.
If you use Google Chrome, the fake browser page sends an HTA file instead of a zip archive.
The injected code is highly-obfuscated... The downloaded zip archive contained a JavaScript file with heavily obfuscated Javascript... This NetSupport RAT-based malware package was sent as a 10MB ASCII text file consisting of hexadecimal characters. This is encoded data, and the file was saved to my lab host and decoded to a zip archive containing the malware package.
Bij een website besmet met SocGholish is een melding te zien die lijkt op een echte browserupdate (bijvoorbeeld Update Chrome/Edge). Deze melding is nep.
Dit botnet maakte gebruik van gestolen inloggegevens om toegang te krijgen tot WordPress-sites.
Socgholish Reconnaissance Commands: ... nltest /dclist
Socgholish Reconnaissance Commands: ... whoami /all ... quser
Socgholish Reconnaissance Commands: net group "Domain Admins" /domain net group "domain admins" /domain
The bot collects a large set of information and sends that to the SocGholish server side which, in turn, returns a payload to the victim system.
Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure.
opère un TDS (Traffic Distribution System)... Monétisation via réseaux publicitaires affiliés : PushHouse, ExoClick... Utilise... Keitaro TDS
266 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
197 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware framework associated here with compromised websites and downstream delivery via dropcaught malicious domains.
Malware receiving inherited infection traffic from expired malicious domains acquired by Shady Squirrel.
Malware traffic recipient associated with scavenged expired malicious domains.
Fake-update malware infrastructure used to deliver malware via scareware and call-center lures.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.