SocGholish
Qu'est-ce que SocGholish ?
SocGholishA JavaScript-based fake-browser-update loader operated by TA569, served from thousands of compromised WordPress sites and used as the initial-access stage for ransomware affiliates including Evil Corp and BlackCat.
SocGholish (a Proofpoint name; also called FakeUpdates) is a JavaScript-based malware framework operated by the threat actor TA569, in continuous activity since 2018 and one of the most prolific initial-access vectors of 2023–2025. Operators compromise WordPress and other CMS-hosted sites at scale via plug-in vulnerabilities or credential reuse, then inject a small loader that profiles the visitor and, for matching targets, redirects to a fake browser-update page (Chrome, Firefox, Edge, Safari) hosting a malicious ZIP. The ZIP contains a JavaScript that fingerprints the host, optionally drops a stealer (NetSupport RAT, AsyncRAT, info-stealers), or hands off to ransomware affiliates including Evil Corp (WastedLocker, LockBit, BlackBasta) and BlackCat. SocGholish increasingly chains with ClickFix-style instructions in 2024–2025, asking the victim to paste a PowerShell command from the fake-update page. Defenses include browser-update warnings (modern browsers update silently and never display in-page update prompts), web-filtering on sites known to be SocGholish-served, blocking JavaScript execution from user-downloaded ZIPs, and EDR rules on the loader's PowerShell stages.
● Exemples
- 01
A user visits a compromised WordPress recipe blog; SocGholish profiles the browser and serves a `chrome_update.js` payload that drops NetSupport RAT.
- 02
A ransomware affiliate receives access from TA569 a few days after an initial SocGholish loader infection and deploys BlackBasta the following week.
● Questions fréquentes
Qu'est-ce que SocGholish ?
A JavaScript-based fake-browser-update loader operated by TA569, served from thousands of compromised WordPress sites and used as the initial-access stage for ransomware affiliates including Evil Corp and BlackCat. Cette notion relève de la catégorie Logiciels malveillants en cybersécurité.
Que signifie SocGholish ?
A JavaScript-based fake-browser-update loader operated by TA569, served from thousands of compromised WordPress sites and used as the initial-access stage for ransomware affiliates including Evil Corp and BlackCat.
Comment fonctionne SocGholish ?
SocGholish (a Proofpoint name; also called FakeUpdates) is a JavaScript-based malware framework operated by the threat actor TA569, in continuous activity since 2018 and one of the most prolific initial-access vectors of 2023–2025. Operators compromise WordPress and other CMS-hosted sites at scale via plug-in vulnerabilities or credential reuse, then inject a small loader that profiles the visitor and, for matching targets, redirects to a fake browser-update page (Chrome, Firefox, Edge, Safari) hosting a malicious ZIP. The ZIP contains a JavaScript that fingerprints the host, optionally drops a stealer (NetSupport RAT, AsyncRAT, info-stealers), or hands off to ransomware affiliates including Evil Corp (WastedLocker, LockBit, BlackBasta) and BlackCat. SocGholish increasingly chains with ClickFix-style instructions in 2024–2025, asking the victim to paste a PowerShell command from the fake-update page. Defenses include browser-update warnings (modern browsers update silently and never display in-page update prompts), web-filtering on sites known to be SocGholish-served, blocking JavaScript execution from user-downloaded ZIPs, and EDR rules on the loader's PowerShell stages.
Comment se défendre contre SocGholish ?
Les défenses contre SocGholish combinent habituellement des contrôles techniques et des pratiques opérationnelles, comme détaillé dans la définition ci-dessus.
Quels sont les autres noms de SocGholish ?
Noms alternatifs courants : FakeUpdates, TA569.
● Termes liés
- malware№ 692
Loader
Malware qui prépare l'environnement et charge des charges utiles ultérieures — souvent directement en mémoire — pour la phase suivante d'une attaque.
- attacks№ 398
Téléchargement furtif (drive-by download)
Attaque où un malware est installé silencieusement sur l'appareil de la victime simplement parce qu'elle visite un site compromis ou malveillant.
- defense-ops№ 597
Initial Access Broker (IAB)
Specialiste cybercriminel qui obtient des acces non autorises a des reseaux d'entreprises et les revend a d'autres criminels, principalement aux affilies de ransomware.
- attacks№ 199
ClickFix Attack
A 2024-vintage social-engineering lure that displays a fake CAPTCHA, error dialog, or 'verify you're human' page instructing the victim to paste a pre-copied PowerShell command into Run, delivering info-stealers or loaders.
- malware№ 1006
Ransomware-as-a-Service (RaaS)
Modèle économique criminel dans lequel les opérateurs de rançongiciel louent leur malware et leur infrastructure à des affiliés qui mènent les attaques et partagent les gains.
- attacks№ 1352
Attaque par point d'eau
Attaque ciblée qui compromet un site web fréquenté par un groupe d'utilisateurs spécifique afin de les infecter lorsqu'ils le consultent.