216.73.217.22

Sayonara, SocGholish: Operation Endgame Disrupts Major Cybercrime Operation

· Published 18/06/2026 16:53

Export JSON

Essential information

Published
18/06/2026 16:53
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
fakeupdates frigidstealer gholoader lockbit operation endgame ransomhub ransomware distribution socgholish traffic distribution system wastedlocker web inject wordpress compromise
Related entities
2 indicators, 2 observables, 1 intrusion sets (apt), 20 techniques (mitre), 6 malware

Description

Global law enforcement, including agencies from the Netherlands, Canada, United States, and Germany, coordinated to disrupt TA569, a prominent cybercriminal group tracked since 2018. The operation targeted infrastructure, taking down over 100 servers and domains while remediating 14,971 compromised websites. TA569 pioneered techniques using fake browser updates to distribute malware, often leading to ransomware attacks. The group compromised high-traffic websites across multiple industries, affecting millions of visitors globally. Their attack chains involved traffic distribution systems like Keitaro TDS and ParrotTDS, delivering payloads that could lead to ransomware deployment in enterprise environments. Law enforcement actions included server disruption and website disinfection, significantly impacting the threat actor's operations, infrastructure, and reputation within the cybercriminal ecosystem.

External references