Researchers reported that threat actor TA2726 used a malicious traffic-distribution framework on 1,509 compromised WordPress sites to turn them into malware delivery gateways. The operation relied on injected fake-plugin JavaScript, admin-ajax bootstrapping, and same-origin REST or query endpoints to profile visitors and selectively redirect them based on geography and device type. Eligible Windows users were funneled into TA569’s SocGholish fake browser update chain, which led to GhoLoader execution, while the broader ecosystem has also routed victims to other payloads including Lumma Stealer, DeerStealer, Marcher, and the macOS stealer FrigidStealer.
Proofpoint previously identified TA2726 as a malicious traffic distribution service working alongside other actors, including TA2727, in web inject campaigns that abuse compromised websites and fake browser update lures across Windows, Android, and macOS. In the newer WordPress-focused activity, the observed s6qgn implant remained active from April through July 2026 even after disruption efforts against parts of the SocGholish ecosystem, and some infected sites were later repurposed for a separate ClickFix injection using Polygon EtherHiding smart-contract lookups. The findings indicate a resilient and increasingly collaborative fake-update ecosystem in which shared infrastructure and compromised websites are reused to deliver multiple malware families and complicate attribution.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Derp published technical details on a malicious WordPress traffic-distribution framework attributed to TA2726, including same-origin REST or query gateways and tokenized state transitions used to turn compromised sites into malware launchpads. The report also noted some infected hosts were later monetized with a separate ClickFix injection using Polygon EtherHiding smart-contract lookups.
Derp reported that the specific TA2726 s6qgn implant was observed on 1,509 compromised WordPress hosts, where injected fake-plugin JavaScript and WordPress admin-ajax bootstrapping were used to profile visitors and selectively redirect eligible Windows users into TA569’s SocGholish chain. The observation window ran from April 21 to July 21, 2026.
Proofpoint disclosed the newly identified macOS stealer FrigidStealer, delivered by TA2727 through browser-themed DMG files on fake update pages. The malware chain tricked users into bypassing Gatekeeper and entering their password.
Proofpoint reported two newly tracked cybercriminal actors, TA2726 and TA2727, involved in web inject campaigns using compromised websites, fake browser update lures, and traffic distribution systems to deliver malware. The report also described TA2726 routing victims by geography and device type to other actors including TA569 and TA2727.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.