ctipilot.ch

Operation Endgame — SocGholish expansion

incident · incident:operation-endgame-socgholish-ta569

Operation Endgame expands to SocGholish/TA569: 106 C2 servers and 14,971 compromised WordPress sites.

Coverage timeline
1
first 2026-06-19 → last 2026-06-19
Peak priority
high
1 high
Sources cited
3
3 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Related entities below
ATT&CK techniques
3
pinned v19.1 · see below

ATT&CK techniques

3 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1189Drive-by Compromise×1

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:

Evidence: 2026-06-19/operation-endgame-expands-to-socgholish-ta569-106-c2-servers · ATT&CK page ↗

Execution TA0002

T1059.007Command and Scripting Interpreter: JavaScript×1

Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.

Evidence: 2026-06-19/operation-endgame-expands-to-socgholish-ta569-106-c2-servers · ATT&CK page ↗

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-06-19/operation-endgame-expands-to-socgholish-ta569-106-c2-servers · ATT&CK page ↗

Story timeline

  1. 2026-06-19Operation Endgame expands to SocGholish/TA569 — 106 C2 servers down, FakeUpdates loader stripped from 14,971 WordPress sites
    active-threats

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

part of

Where this entity is cited

  • active-threats1

Source distribution

  • helpnetsecurity.com1 (33%)
  • politie.nl1 (33%)
  • proofpoint.com1 (33%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Operation Endgame — SocGholish expansion (1)

2026-06-19 · view entry permalink →

HIGH

Operation Endgame expands to SocGholish/TA569 — 106 C2 servers down, FakeUpdates loader stripped from 14,971 WordPress sites

A coordinated law-enforcement action on 2026-06-18 — an expansion of the May 2024 Operation Endgame — dismantled infrastructure tied to TA569, the long-running operator of the SocGholish (FakeUpdates) initial-access framework (Politie, 2026-06-18; Help Net Security, 2026-06-18). The Dutch National High Tech Crime Unit led the operation with the RCMP, FBI, BKA and Europol; 106 command-and-control servers were taken down and the malicious JavaScript loader was removed from 14,971 compromised WordPress sites. SocGholish injects obfuscated JavaScript into legitimate WordPress sites (typically via stolen wp-admin credentials or vulnerable plugins), fingerprints visitors and renders a fake browser-update lure; accepting it drives a ZIP download of a .js/.lnk stage-1 that executes through wscript.exe or mshta.exe (T1189 Drive-by Compromise → T1059.007 JavaScript → T1204.002 User Execution), historically passing access to Evil Corp downstream affiliates (Proofpoint, 2026-06-18). This is the first Endgame phase to directly target the FakeUpdates component, an initial-access mechanism in continuous use since roughly 2017.

threat19 Jun 05:20Zmulti-sourceOpen finding ↗