SocGholish's Intrusion Techniques Facilitate Distribution of RansomHub Ransomware
Essential information
- Published
- 14/03/2025 10:16
- Modified
- 14/03/2025 19:30
- Tags
- 2025-03-14 backdoor compromised websites credential-theft javascript keitaro tds ransomhub ransomware socgholish
- Related entities
- 1 intrusion sets (apt), 25 techniques (mitre), 2 malware, 6 others
Description
SocGholish, a malware-as-a-service framework, is being used to deploy RansomHub ransomware. It compromises legitimate websites, redirecting visitors to fake browser updates that deliver malicious payloads. The highly obfuscated JavaScript loader evades detection and executes various tasks, including reconnaissance, credential theft, and backdoor deployment. Water Scylla, the group behind this activity, collaborates with threat actors operating rogue Keitaro TDS instances for payload distribution. The attack chain involves multiple stages, from initial access to ransomware deployment. SocGholish's versatile loader can download and execute malicious payloads, exfiltrate data, and execute arbitrary commands. Recent detections show high activity in the US, primarily targeting government organizations.