Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

Operation Endgame Disrupts SocGholish Servers, Cleans 14,971 WordPress Sites

https://thehackernews.com/2026/06/operation-endgame-disrupts-socgholish.html

Publish Date: 2026-06-19 11:07:00

Source Domain: thehackernews.com

International law enforcement agencies, including those from the Netherlands, Canada, Germany, and the U.S., have dismantled the malicious infrastructure of the SocGholish botnet and cleaned up almost 15,000 infected WordPress websites. This joint operation aims to prevent further cyber damage globally, reduce malware spread, and minimize the risk of using these systems to attack critical infrastructure. The initiative, under Operation Endgame, has taken down 106 servers associated with SocGholish and purged infections from 14,971 WordPress sites. The malware, known since 2017, acts as a conduit for various high-level threats, such as ransomware and espionage, distributed via deceptive software updates on compromised websites. The collaboration seeks to tackle the webinject and traffic distribution system ecosystem powered by SocGholish, which targets almost every industry sector globally. The majority of the targeted sites were based in the U.S., followed by several European and Asian countries. Furthermore, the threat actors behind SocGholish often collaborate with other traffic distribution systems and affiliates to broaden their reach and evade detection.

Key Points:
– International law enforcement dismantled the SocGholish botnet’s infrastructure, cleaning up over 14,000 infected WordPress websites.
– Operation Endgame targeted 106 servers and prevented cybercrimes involving ransomware, espionage, and other cyber attacks.
– SocGholish often collaborates with traffic distribution systems and other threats, impacting a wide range of industry sectors globally.
– The majority of compromised websites were located in the U.S., followed by other countries in Europe and Asia.
– Collaboration with other threat actors and exploiting various distribution techniques enhance SocGholish’s reach and evasiveness.