Russian state-linked threat actors have leveraged the SocGholish (also known as FakeUpdates) JavaScript loader to target U.S.-based organizations, including a civil engineering company with ties to Ukraine. SocGholish, operated by TA569, acts as an initial access broker by distributing fake browser update alerts on compromised websites, tricking users into downloading malicious JavaScript that installs additional malware. In a recent campaign, the RomCom threat actor used SocGholish to deliver the Mythic Agent malware, marking the first observed instance of this payload being distributed via SocGholish.
The activity has been attributed with medium-to-high confidence to Unit 29155 of Russia's GRU, highlighting the ongoing use of sophisticated malware delivery chains for both cybercrime and espionage. The attacks exploit vulnerabilities in website plugins to inject malicious code, and SocGholish's services are known to be used by various threat groups, including Evil Corp, LockBit, Dridex, and Raspberry Robin. The campaign underscores the evolving tactics of Russian-aligned actors in targeting U.S. entities through layered malware distribution strategies.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On November 26, 2025, Arctic Wolf Labs publicly reported the incident as the first observed case of a RomCom payload being distributed via SocGholish. The company attributed the activity with medium-to-high confidence to Russia's GRU Unit 29155 and highlighted RomCom's continued focus on Ukraine-related targets.
The intrusion attempt was stopped before it could progress, with Arctic Wolf reporting that its endpoint defenses detected and blocked the malicious loader. As a result, the attempted compromise of the U.S. firm was successfully averted.
Roughly 10 minutes after initial exploitation, and within 30 minutes of the SocGholish infection, the attackers delivered a RomCom-linked DLL loader disguised as msedge.dll. The loader checked the victim's Active Directory domain before executing and then attempted to launch Mythic Agent and related tooling including VIPERTUNNEL.
In September 2025, attackers used SocGholish fake browser update lures on compromised websites to target a U.S.-based civil engineering company that had worked for a city with close ties to Ukraine. The operation represented a highly targeted intrusion against a Ukraine-linked U.S. organization.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcethehackernews.com
Open sourcesecurityonline.info
Open sourcescworld.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.