Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Quantum Systems and Tencore expand defence robotics production with new German manufacturing hub

    June 20, 2026

    Better than the Google TV Streamer?

    June 20, 2026

    The upcoming Star Fox 64 remake is too conservative, but wouldn’t you overcorrect after a disaster like Star Fox Zero?

    June 20, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Quantum Systems and Tencore expand defence robotics production with new German manufacturing hub
    • Better than the Google TV Streamer?
    • The upcoming Star Fox 64 remake is too conservative, but wouldn’t you overcorrect after a disaster like Star Fox Zero?
    • I’ve tried nearly every iOS 27 feature, and these 3 are why I’m still excited about the update
    • 16 Best Greens Powders (2026): Taste-Tested for Months
    • Waymo Has Been Defeated by New York City
    • The Hidden Money Mistakes Costing Digital Nomads More Than They Realize
    • New Prinz Eugen ransomware prioritizes recent files for encryption
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown 
    Cybersecurity

    15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown 

    kirklandc008@gmail.comBy kirklandc008@gmail.comJune 20, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Botnet
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Law enforcement agencies in four countries, working with Europol and private partners, have disrupted SocGholish infrastructure and cleaned up nearly 15,000 infected WordPress websites.

    Active since 2017 and also known as FakeUpdates, SocGholish is a malware framework injected into websites running popular content management systems, such as WordPress, Joomla, and Drupal, either via known vulnerabilities or stolen credentials.

    The framework acts as a JavaScript-based dropper, deploying various malware families as part of drive-by downloads, including ransomware, banking trojans, spyware, and more, and has been one of the most used loaders for years.

    SocGholish is operated by a Russian-speaking threat actor tracked as DEV-0206, Gold Prelude, Mustard Tempest, TA569, and UNC1543, which acts as an initial access broker and has been associated with the infamous Evil Corp gang (believed to be linked to Russian intelligence).

    TA569 has been observed indiscriminately compromising websites to inject the SocGholish loader, including prominent media and retail portals visited by millions of users daily.

    The malware profiles a victim’s browser, performs specific checks, and then overwrites the entire webpage with a fake browser update to entice the user into downloading a malicious payload, Proofpoint explains.

    Advertisement. Scroll to continue reading.

    Orange’s cyber defense unit observed SocGholish delivering loaders like Gholoader and MintsLoader, which eventually led to payloads such as the GhostWeaver PowerShell backdoor, LockBit and RansomHub ransomware, and AsyncRAT or NetSupport RAT backdoors.

    According to Infoblox, approximately 55% of cloud customers were exposed to SocGholish this year, which demonstrates the high risk the botnet poses to enterprises worldwide.

    The ShadowServer Foundation puts that into better perspective: in May, there were more than 1.44 million compromised WordPress websites available for use by SocGholish.

    Authorities in the Netherlands, Canada, the US, and Germany, with support from Europol, took down 106 command-and-control (C&C) servers and domains associated with SocGholish, and removed backdoors and malware from 14.971 infected WordPress websites.

    The Dutch police say notifications were also sent to WordPress site owners whose compromised credentials were identified, urging them to change their logins, enable MFA, delete suspect accounts, and keep their sites updated.

    Related: Dutch Police Dismantle Massive 17-Million-Device Botnet

    Related: GlassWorm Botnet Disrupted

    Related: Tycoon 2FA Fully Operational Despite Law Enforcement Takedown

    Related: SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown

    botnet cleaned SocGholish Takedown websites WordPress
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    New Prinz Eugen ransomware prioritizes recent files for encryption

    June 20, 2026

    Google sets timeline for Android developer verification enforcement

    June 20, 2026

    Apple confirms price increases are coming – how much will it cost you?

    June 20, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Nothing CEO says phone prices are going to keep going up

    June 12, 20267 Views

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Quantum Systems and Tencore expand defence robotics production with new German manufacturing hub
    • Better than the Google TV Streamer?
    • The upcoming Star Fox 64 remake is too conservative, but wouldn’t you overcorrect after a disaster like Star Fox Zero?
    • I’ve tried nearly every iOS 27 feature, and these 3 are why I’m still excited about the update
    • 16 Best Greens Powders (2026): Taste-Tested for Months

    Quantum Systems and Tencore expand defence robotics production with new German manufacturing hub

    June 20, 2026

    Better than the Google TV Streamer?

    June 20, 2026

    The upcoming Star Fox 64 remake is too conservative, but wouldn’t you overcorrect after a disaster like Star Fox Zero?

    June 20, 2026

    I’ve tried nearly every iOS 27 feature, and these 3 are why I’m still excited about the update

    June 20, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.