Dutch law enforcement agencies working with similar agencies in Germany, Canada and the United States have broken up a criminal network using the malicious software called SocGholish. They removed nearly 15,000 infected WordPress websites.
Maikel Rollman of the Netherlands National High Tech Crime Unit said, "With these actions we prevent criminals from having access to infected computer systems. This also prevents further harm to the digital systems of people, companies and organizations around the world. This will limit the spread of malware and reduce the chance that those systems are used for cyberattacks on critical infrastructure and other vital societal processes. Today's actions mark the start of continued action against SocGholish."
Operation Endgame is an international law enforcement effort that began in 2024 to disrupt botnets and eliminate criminal networks that support them. As part of this operation, law enforcement took down 106 servers connected to SocGholish and eliminated the infection from 14,971 WordPress sites. Law enforcement notified each website owner about what needed to be done to clean up their CMS, change their credentials and remove all suspect accounts.
SocGholish, also known as Fake Updates, is a JavaScript (JS)-based downloader malware that was first discovered in 2017. SocGholish is a typical way that threat actors (e.g., Evil Corp aka DEV-0243/Indrik Spider/UNC2165; LockBit; Ransom Hub; Dridex and Raspberry Robin aka Roshtyak) gain initial access to victim machines. Once SocGholish is installed on a victim machine, the threat actors can continue to target that machine using ransomware and/or espionage.
The malware spreads via compromised websites presenting themselves as fake updates for commonly used software like Google Chrome or Mozilla Firefox. The individuals behind the malware operate under several pseudonyms including: Gold Prelude, Mustard Tempest, Purple Vallhund, TA569 and UNC1543.
Silent Push identified how SocGholish infections occur. They stated that "website infections may come about from multiple types of compromise. For example, SocGholish infections can result from direct injection, where SocGholish will insert JS directly onto a webpage loaded with the SocGholish payload. Additionally, there is a variation of direct injection which utilises an intermediate JS file to load the related injection onto the webpage."
Arctic Wolf recently reported that SocGholish was being utilised by RomCom to distribute the Mythic Agent. This demonstrated that an Initial Access Broker (IAB) is able to provide services to many actors who seek varying objectives.
Infected WordPress Sites By Country
Orange Cyberdefense mentioned that SocGholish delivers loaders including another JavaScript-based loader called GhoLoader, and Mints Loader. These loaders subsequently introduce secondary payloads including GhostWeaver, LockBit, AsyncRAT, and NetSupport RAT. Orange Cyberdefense stated "the layers involved in SocGholish enable multiple categories of subsequent payloads. Furthermore, SocGholish works in collaboration with Traffic Distribution System (TDS) providers like TA2726."
Traffic Distribution Systems utilise algorithms to redirect site visitors to different locations depending on characteristics of those visitors. Examples include redirecting visitors to a fake login page displaying a phishing attack, redirecting visitors to a fake software update page requesting that the visitor download an update containing malware, or other forms of malicious software. The goal is to allow attackers to gain access to victim networks and conduct financially motivated activities such as ransomware or other scams.
Cybercrime groups use TDS to bypass existing firewalls preventing visitors from accessing malicious websites, and to collect IP addresses, operating systems, geography, hardware, and browser data from potential victims so they can identify potential targets.
Once a visitor reaches the TDS, the attacker typically exploits the visitor's device at the end of the redirection chain through various social engineering tactics by delivering phishing pages, financial scams and other malware.
According to the Shadowserver Foundation, the majority of the compromised WordPress sites have had criminal infrastructure added by SocGholish. Most of the hacked sites were hosted within the United States, followed by Germany, France, India, Brazil, Singapore, Italy, Indonesia, Canada and Vietnam.
Shadowserver stated: "One method of abuse is through Domain Shadowing." Domain shadowing allows a threat actor to gain access to a legitimate domain's authoritative DNS provider or registrar account panel. Using their access to that account panel, a threat actor can quietly add new subdomains below the main ("apex") domain owned by the legitimate domain owner. Those malicious subdomains are often named after common hostnames intended to appear innocuous among legitimate DNS entries of the domain owner's legitimate DNS infrastructure. However, those malicious subdomains will reference external malicious infrastructure run by a threat actor.
This makes it much easier for an attacker to conceal malicious activity, while also making it difficult for defenders to quickly identify or block illicit activity, by hiding malicious activity in plain sight through piggybacking off the legitimacy of a domain.
An overview of some of the key players who bring victims to SocGholish
Proofpoint noted that while SocGholish compromises a wide variety of websites (i.e. nonprofit websites, school websites, etc.), they "indiscriminately compromise websites" and tend to favour high-traffic websites.
"Website compromise by TA569 is opportunistic. Higher traffic websites result in more victims," Proofpoint stated. "Additionally, the actor has compromised websites in just about every industry: non-profits/schools/hospitals/legal/realtor/etc."
Infoblox stated that SocGholish is a multi-staged JavaScript framework that transforms compromised websites into vehicles capable of downloading malware onto visitor computers (drive-by downloads). The framework enables four primary stages: traffic acquisition, traffic filtering, lure payload and on-device implant execution.
Infoblox noted that TA569 compiles an enormous list of websites that they compromise, but TA569 also accepts traffic from affiliates. The arrangement is commercial in nature: when a user visits one of these compromised websites, the affiliate will fingerprint that user and pass the user to SocGholish via an embedded link. In exchange for this service, the affiliate is rewarded monetarily for each "lead".
Some notable affiliates that have sold traffic to SocGholish over time include: TA2726, Parrot TDS, JunkyTDS, Keitaro and zTDS. Other commercial solutions were available for use by threat actors to filter traffic for SocGholish or forward traffic to either the original website or any other content based on whether or not the visitor meets specific criteria.
Data collected by Infoblox indicates that 55 percent of its cloud customers made attempts to connect with SocGholish during 2022 alone. Nearly every industry sector has been impacted by attacks involving SocGholish over the course of five months. Some of the industries most heavily impacted include: Government, Education, Banking, Healthcare, Non-IT Services, Financial Services, IT Consulting, Utilities, Insurance and Transportation.
This illustrates "that SocGholish is not a vertically focused threat limited to one single sector", states Infoblox. Instead, SocGholish's webinject/TDS ecosystem is massive in scope and is capable of reaching both publicly funded sectors and commercially significant sectors, thereby making SocGholish a threat relevant across its entire customer base.