SocGholish (FakeUpdates) infections begin when victims execute a JavaScript browser-update lure from a compromised website, commonly launching wscript.exe through the default Windows Script Host association. In a documented intrusion attributed to initial-access broker TA582, operators performed domain discovery, browser credential theft, NTLM-hash theft, DLL sideloading, staging, and scheduled-task persistence, then maintained access for roughly 30 days. A later operator—suspected, but not confirmed, to be linked to RansomHub—added reverse SSH/proxy persistence, extracted registry hives and credentials, and modified Outlook signatures with malicious SMB URLs to capture NetNTLM hashes; the incident was contained before ransomware deployment.
Post-compromise activity included use of stolen credentials over WinRM, with an injected RtkAudUService64.exe process authenticating to remote systems and wsmprovhost.exe performing reconnaissance, scheduled-task actions, and credential-access-related activity. Detection guidance covers browser-parented wscript.exe, cscript.exe, PowerShell, pwsh, or mshta; script hosts redirecting command output to temporary files; registry changes that disable NTLM sending restrictions for Internal Monologue hash theft; suspicious DNS queries from scripting or native processes; and WinRM-linked scheduled tasks or NTDS/shadow-copy tooling. Organizations should also consider using GPO to associate .js files with a non-executing application such as Notepad, while tuning detections for legitimate administration and automation.

Get the actors, campaigns, and ATT&CK mapping behind it.
10 events from the most recent confirmed update back to the earliest known activity.
ShroudCloud published the stable high-severity Sigma rule “Suspicious DNS Request from High-Risk Process.” It identifies DNS queries by scripting or native Windows processes to specified suspicious TLDs or tunneling and paste-service domains, for potential ClickFix, SocGholish, and similar campaign activity.
ShroudCloud published the stable medium-severity Sigma rule “Script Host Piping Output to Temporary Files.” It detects wscript.exe or cscript.exe spawning command or PowerShell processes that redirect output into .tmp files, a staging pattern observed in FakeUpdates intrusions.
ShroudCloud published the stable, high-severity Sigma rule “Browser Spawning Script or Shell Execution.” The rule detects browsers launching wscript, cscript, PowerShell, pwsh, or mshta, including the FakeUpdates pattern in which Chrome launches Update.js.
ShroudCloud published the stable high-severity Sigma rule “NTLM Hash Theft via Internal Monologue.” It detects registry changes setting RestrictSendingNTLMTraffic to DWORD value 0, which can weaken NTLM restrictions and enable hash extraction without directly accessing LSASS.
The intrusion was stopped before the suspected ransomware operator performed actions on objectives or deployed a ransomware payload.
The later-stage operator modified Outlook HTML signature files to include attacker-controlled file:// SMB URLs, causing recipients’ email clients to attempt SMB authentication. This could expose NetNTLM hashes for theft or relay attacks and aid email-contact reconnaissance.
The operator created SYSTEM scheduled tasks including Update, which used ssh.exe for a reverse SSH tunnel over port 443, and fontdrvr1, which executed a Python script; libffi and libfi were additional persistence names. The actor also injected RtkAudUService64.exe, used WinRM for remote reconnaissance and scheduled-task activity, accessed shadow copies and registry hives, and again copied browser credential data.
After an approximately 30-day dwell period, a second operator—suspected but not confirmed to be a RansomHub affiliate—took over the intrusion and conducted network, account, session, and administrative-share discovery.
The SocGholish/FakeUpdates activity on a domain-joined host performed discovery, browser credential collection, and Internal Monologue NTLM-hash theft. It established persistence with OneDriveStandaloneUpdater and python-pip scheduled tasks, prepared DLL sideloading, and installed an embedded Python environment.
A Canadian outdoor magazine WordPress site was compromised and injected with traffic-distribution JavaScript. A visitor clicked an “Update Browser” prompt, causing Chrome to launch wscript.exe and execute the downloaded Update.js payload.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
10 references tracked. Mallory keeps watching after this page renders.
shroudcloud.io
Open sourceshroudcloud.io
Open sourceshroudcloud.io
Open sourceresearch.nccgroup.com
Open sourceshroudcloud.io
Open sourcemedium.com
Open sourceredcanary.com
Open sourceesentire.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.