Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Researchers Trick AI Browsers Into Leaking Credentials

June 24, 2026

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

June 24, 2026

macOS Backdoor Uses Prompt Injection to Evade AI Triage

June 24, 2026
Facebook X (Twitter) Instagram
Wednesday, June 24
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Operation Endgame Disrupts Malware Linked to Major Ransomware Gang
News

Operation Endgame Disrupts Malware Linked to Major Ransomware Gang

Team-CWDBy Team-CWDJune 19, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A major cybercriminal network involving thousands of infected websites used to distribute malware has been disrupted by an international law enforcement takedown.

The action against the SocGholish malware group formed the latest part of Operation Endgame, an ongoing global police investigation to combat ransomware and cybercrime worldwide.

Announced by the Dutch police on June 18, action was taken to remediate infections of 15,000 websites controlled by SocGholish group and to dismantle the botnet associated with the group.

Notably, the SocGholish botnet was regularly used by Evil Corp, the notorious, Russia-based ransomware and cyber crime group behind a swath of destructive malware attackers worldwide, including against governments, healthcare institutions and enterprises.

SocGholish hacked or used previously leaked credentials to gain access to legitimate WordPress sites. As detailed by Proofpoint, which tracks SocGholish as TA569, these compromised websites were used to push malicious pop-ups to visitors, which told users that they were using out-of-date software which needed updating.

If the user installed the ‘update’ they became infected with malware and roped into the SocGholish botnet, used to deliver malware and ransomware to further victims.

The international law enforcement has taken action against SocGholish has seen the takedown of 106 servers and domains associated with the malware, as well as remediating infections of the compromised websites.

 ‘With these actions we deprive cybercriminals of access to infected computer systems. This prevents further damage to the digital systems of citizens, businesses and organizations worldwide and limits the spread of malware,” said Maikel Rollman of the Netherlands National High Tech Crime Unit (NHCTU).

“It also reduces the risk that these systems are used for cyber‑attacks on critical infrastructure and other essential societal processes. This marks the beginning of further action against SocGholish,” he added.

Read more: Why Ransomware Remains One of Cybersecurity’s Most Persistent and Costly Threats 

The coordinated action took place over a week was taken jointly by specialist agents and officers at the NHCTU, the Royal Canadian Mounted Police (RCMP), the German Federal Criminal Police Office (BKA) and the US Federal Bureau of Investigation (FBI). The action also received support from Europol, Eurojust and cybersecurity industry partners.

“SocGholish is not a niche threat. Their activities reach deep into public sector and commercial environments, paving the way for other cybercriminals to gain access to networks”, said Dr. Renée Burton, vice president of Infoblox Threat Intel, one of the industry partners which supporting the action.  

The owners of the compromised websites have been informed about what happened and urged to change their login credentials, as well as update the sites with the necessary security patches..

The owners of WordPress sites have also been issued with the following advice:

  • Change their login credentials
  • Enable multi‑factor authentication
  • Delete any unknown additional WordPress accounts
  • Keep their WordPress site up‑to‑date in the future



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNew Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets
Next Article INTERPOL Operation Takes Down Sniper Dz Phishing Platform, Arrests Administrator
Team-CWD
  • Website

Related Posts

News

Researchers Trick AI Browsers Into Leaking Credentials

June 24, 2026
News

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

June 24, 2026
News

macOS Backdoor Uses Prompt Injection to Evade AI Triage

June 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What is it, and how do I get it off my device?

September 11, 2025

Children and chatbots: What parents should know

January 23, 2026

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.