Cyber — 2026-06-19
Operation Endgame Dismantles SocGholish Malware Network Linked to Russia Evil Corp Seizing 106 Servers
BLUFDismantling 106 servers degrades but likely does not eliminate SocGholish's distribution capacity by year-end 2026, as the upstream traffic distribution network and exposed credential pools remain intact.
A joint action week involving the Netherlands, Canada, the United States, and Germany dismantled 106 servers and domains and remediated 14,971 infected WordPress websites, the Dutch National Police announced on June 18 1Operation Endgame Disrupts Malware Linked to Major Ransomware Gang" data-source="Infosecurity Magazine" data-url="https://www.infosecurity-magazine.com/news/operation-endgame-socgholish-evil/" data-otype="trade_press">23. Dutch authorities identified SocGholish as a primary delivery mechanism for Evil Corp, a Russia-based criminal group sanctioned by Western governments and linked to the WastedLocker, LockBit, and RansomHub ransomware families 14. Proofpoint, which contributed intelligence to the operation and tracks the group as TA569, reported that compromised sites included properties with millions of daily visitors across healthcare, media, and legal sectors 4. Victim notifications were distributed through HaveIBeenPwned and Shadowserver, with site owners urged to rotate credentials and enable multi-factor authentication 1.
AnalysisTA2726, the traffic distribution service feeding TA569 payloads, was largely unaffected, preserving the delivery apparatus that routes victims to malicious inject pages. With approximately 1.4 million WordPress login credentials still exposed, Evil Corp-linked actors will
likely reconstitute a functionally equivalent JavaScript injection network at 500 or more newly compromised sites by year-end 2026. Analytic confidence is moderate: both primary sources trace to the Dutch National Police announcement and Proofpoint's coordinated disclosure, with no independent corroboration outside the joint law enforcement narrative. The seized infrastructure may instead have reached Evil Corp's financial clearing and command-tier components, suppressing reconstitution well beyond that window. Security teams in healthcare, media, and legal cannot draw down browser-injection monitoring or credential hygiene programs until that question resolves.
4 sources
- International law enforcement initiate hunt on malware group SocGholish - Dutch National Police
- Operation Endgame Disrupts Malware Linked to Major Ransomware Gang - Infosecurity Magazine
- Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp - Bleeping Computer
- Sayonara, SocGholish: Operation Endgame Disrupts Major Cybercrime Operation - Proofpoint
View in full brief →