Police Clean Nearly 15,000 SocGholish-Infected Sites, Takedown 100+ Servers Tied to Evil Corp
International law enforcement agencies have cleaned malware from nearly 15,000 WordPress sites and taken down over 100 servers linked to the SocGholish botnet and the Russian cybercrime group Evil Corp.

International law enforcement agencies have cleaned nearly 15,000 malware-infected WordPress websites and taken down more than 100 servers linked to the SocGholish botnet and the Russian cybercrime group Evil Corp. The joint action, supported by Europol and Eurojust, was part of Operation Endgame, a major law enforcement operation targeting cybercrime infrastructure.
Authorities from the Netherlands (NHCTU), Canada (RCMP), the United States (FBI), and Germany (BKA) cleaned SocGholish malware infections from 14,971 compromised WordPress websites and took 106 servers and domains offline. The Dutch police removed the malware and backdoors from the infected sites, and advised website owners to change their credentials, enable multi-factor authentication, delete unknown WordPress accounts, and keep their sites up to date.
"With these actions we deprive cybercriminals of access to infected computer systems. This prevents further damage to the digital systems of citizens, businesses and organizations worldwide and limits the spread of malware," said Maikel Rollman of the Netherlands' National High Tech Crime Unit. "It also reduces the risk that these systems are used for cyber-attacks on critical infrastructure and other essential societal processes. This marks the beginning of further action against SocGholish."
The SocGholish JavaScript-based malware downloader (also tracked as FakeUpdates and GhoLoader) has been used in attacks since at least 2017. It works by hijacking legitimate websites—primarily WordPress sites—and tricking visitors into downloading malicious payloads disguised as fake browser updates. When a user installs the malicious update, the malware opens a connection to the attackers, giving them access to the infected system.
SocGholish has been used to deploy other malware families, including Dridex, Doppelpaymer, Empire, Koadic, Chtonic, and Azorult. The malware has been previously linked to Evil Corp, a Russian cybercrime gang active since 2007 that has been associated with the Zeus and Dridex malware families and was behind the WastedLocker, Hades, Macaw Locker, and Phoenix CryptoLocker ransomware operations.
In November, as part of Operation Endgame, law enforcement agencies also took down over 1,000 servers used by the Rhadamanthys, VenomRAT, and Elysium botnet malware operations. Previously, Operation Endgame has targeted ransomware infrastructure, Smokeloader botnet customers and servers, the AVCheck site, and various other major malware operations, including DanaBot, IcedID, Pikabot, Trickbot, Smokeloader, Bumblebee, and SystemBC.
This operation underscores the ongoing collaborative efforts to disrupt Evil Corp's criminal operations at scale. The takedown of over 100 servers and the cleaning of nearly 15,000 infected sites represents a significant blow to the infrastructure that has been used to distribute ransomware and other payloads for years.
The Dutch National Police announced the takedown, which also included notifying and cleaning nearly 15,000 compromised WordPress sites. Infoblox researchers noted that TA569 may have controlled up to a million sites over its history, and while the action will disrupt SocGholish operations, the group's ability to rebuild infrastructure or shift to new delivery models remains uncertain.
The latest update from Operation Endgame reveals that 106 servers and 101 domains were seized, and nearly 15,000 infected WordPress sites were remediated, with leaked credentials from 1.4 million WordPress sites found. Law enforcement agencies from the Netherlands, Canada, the US, and Germany, supported by Europol and Eurojust, conducted the joint action week. Dutch police removed backdoors and malware from all identified infected sites and notified affected owners through platforms including HaveIBeenPwned, DIVD, Spamhaus, and The Shadowserver Foundation. The operation signals continued expansion against SocGholish operators and affiliated cybercriminal networks.
The CyberScoop report adds that the takedown was conducted under Operation Endgame (a multinational effort since 2024) and, for the FBI, Operation Riptide. It also notes that the FBI issued a public service announcement warning about traffic distribution system (TDS) attacks used for credential theft, financial scams, and network intrusions. Proofpoint described Evil Corp as the 'grandfather' of this threat type, emphasizing the group's prominence in compromising websites with TDS to redirect users to malware.
The takedown, part of Operation Endgame, involved law enforcement and private partners dismantling 106 command-and-control servers and domains linked to the SocGholish botnet. This operation led to the cleanup of approximately 15,000 compromised WordPress websites that were used to distribute the malware, which is also known as FakeUpdates and serves as a JavaScript-based dropper for ransomware and info-stealers.
Law enforcement flagged the action as part of the ongoing Operation Endgame crackdown, which has previously targeted initial access botnets, bulletproof hosting, and information-stealing services. Dutch police confirmed that 154,000 email addresses and over half a million previously unseen passwords were recovered from the operation, and that notifications to affected WordPress site owners were coordinated through HaveIBeenPwned, DIVD, Spamhaus, and the Shadowserver Foundation. Evil Corp, whose members operate beyond the reach of Western law enforcement, continues to be tied to Zeus and Dridex malware as well as major ransomware and money-laundering operations, police said.
The Dark Reading report adds context on the role of traffic distribution systems (TDSs) in the SocGholish infection chain, noting that the FBI Cyber Division issued a public service announcement warning enterprises about TDS abuse. Infoblox analysis cited in the article found that nearly 55% of customer networks attempted to reach SocGholish infrastructure over a five-month period, with government, education, and healthcare sectors most targeted. The piece also details how TA569 affiliates use commercial TDS platforms like Keitaro alongside underground tools such as ParrotTDS and JunkyTDS to filter victims and deliver follow-on ransomware payloads.