On June 18, 2026, a 3-year sealed international investigation unsealed. Dutch police, FBI, RCMP, and BKA dismantled the SocGholish botnet —
seen from United States

seen from United Kingdom
seen from Saudi Arabia
seen from Australia

seen from Mexico
seen from Ireland

seen from Netherlands
seen from United States

seen from Bosnia & Herzegovina

seen from India

seen from Argentina
seen from Singapore
seen from United Arab Emirates

seen from India
seen from Russia
seen from United States
seen from Indonesia

seen from United Kingdom
seen from Hong Kong SAR China
seen from Malaysia
On June 18, 2026, a 3-year sealed international investigation unsealed. Dutch police, FBI, RCMP, and BKA dismantled the SocGholish botnet —

Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
Free to watch • No registration required • HD streaming
Score Another One For Operation Endgame
SocGholish, the ‘drive by’ malware-as-a-service group known mostly for fake updates and brute force credential theft, has been disrupted by the international co-op Operation Endgame. I’ve reported on each of these separately in the past, covering SocGholish here, and earlier disruptions carried out by Operation Endgame here. The result of this campaign was the takedown of over a hundred domains in attacker control and the remediation of nearly 15K compromised WordPress sites.
WordPress is one of the largest platforms for deploying websites on the internet, and as such is a common target of threat actors. According to ShadowServer’s article on this disruption, as of June 2026 over 43% of websites are powered by the platform globally, many of them small to medium sized enterprises and individuals. SocGholish, which is also known as DEV-0206, GOLD PRELUDE, Mustard Tempest, TA569 and UNC1543, uses Traffic Direction/Distribution Systems (TDS) to redirect users to hijacked or malware injected secondary sites, usually legitimate but compromised, thus spreading their payload with opportunistic attacks rather than targeted ones. This is what sets SocGholish apart from phishing scammers; it’s less baiting victims and more ambushing them. Additionally the group practices ‘domain shadowing’, whereupon they gain access to the DNS providers and hosts. Infiltrating these processes at the first tier of traffic between sites means they in essence hide behind the legitimacy of these domains, and bypass security measures via exploitation of the established trust in them. Part of the difficulty in pinning SocGholish down has been the rapid turnover in domain cycling which is a hallmark of the group’s infrastructure. Defenders can find one, but the group simply moves on to the next.
This coordinated disruption was carried out last week by authorities from the Netherlands (NHCTU), Canada (RCMP), the United States (FBI) and Germany (BKA), with support from Europol and Eurojust, as well as private sector partners such as Infoblox (who also covered the campaign), Proofpoint and The Shadowserver Foundation. In total, 14,971 compromised legitimate WordPress sites infected with SocGholish malware were remediated and 106 servers and domains were taken down worldwide, disrupting the SocGholish botnet.
Victims of the compromised sites are urged to do the usual hardening of their systems: immediately change their login credentials, enable multi‑factor authentication (MFA/2FA), check for and delete any unknown additional WordPress accounts that have been added, and patch their WordPress site and keep their software and plugins up‑to‑date in the future. Furthermore, ShadowServer has provided a special report site to inform site owners and other potential victims not already notified if they are part of the list of the compromised sites. For everyone else, the same advice applies that always does: don’t click an untrusted link. SocGholish works by tricking users into clicking a popup that then redirects them to a secondary site where they download the malware through an alleged update. Real updates will always come from the vendor or system settings. This disruption is not likely to be the end of the group, but it is a significant win just the same.
Posted, 6/22/26
Hooray For Our Side
I feel like I do nothing but report on new vulnerabilities, new leaks, new breaches, DNS outages and otherwise negative results to negative circumstances. But today there is good news: Operation Endgame’s latest disruption.
First seen in May of 2024, the cooperative initiative between Europol and other law enforcement agencies on a global scale was responsible for taking down IcedID, SystemBC and others in what became a shutdown of over a hundred servers, arrests of many High Value Targets and freezing illegal assets. A second campaign, in May of this year, took down even more, focused on malware families such as Lactrodectus, HijackLoader and Trickbot. 300 servers worldwide, issued arrest warrants for 20 new targets, 650 domains neutralized.
And now, in its third ‘season’, Operation Endgame has successfully disrupted Rhadamanthys Stealer, Venom RAT and the Elysium botnet. Over a thousand servers have been taken down along with 20 more domains. In all of these cases, millions were seized in cryptocurrency funds, and hundreds of thousands of victims, at the very least, were defended. Most of whom may not have known they were infected with anything at all.
Ransomware is arguably the biggest threat to global digital traffic, with malware families such as these being among the top vectors for its delivery. And while they won’t disappear completely – I covered the resurgence of Lactrodectus not that long ago, in fact – disruptions of this magnitude should nevertheless be celebrated.
Cybersecurity faces challenges on both sides of the fight. Threat actors have the advantage of failure, meaning that if a thousand attacks net only a hundred infections, that’s still considered a successful campaign. Whereas SOC teams that fail to do their job even once face losing them entirely. And it’s not like threat actors just give up. As I mentioned, Lactrodectus returned, and quickly. After disruption in May, it was being reported as active again in July. I have no doubt that Rhadamanthys and Venom RAT will follow the same pattern; we’ll see them again.
And therein lies the other challenge: users. People will always fall for phishing, they’ll always try to cut corners somewhere and leave themselves vulnerable to compromise, they’ll fail to update patches that would otherwise keep these things out. It’s a never ending, uphill battle that isn’t always necessarily their fault. Even the most cautious among us can be fooled. Attack campaigns are getting more clever and sophisticated, automation via AI means that there are no ‘off’ hours, and we’re moving into the season where social engineering will shift focus onto holiday related exploitation.
Still, this is a big win and deserves recognition as such. If I may make a Tron reference again, in the words of Kevin Flynn, exhausted and overwhelmed but not defeated: hooray for our side.
Posted on LinkedIn, 11/13/25
By accident, I learned that one of the movies I covered in Season 4 of my YouTube show is Free With Ads on YouTube. https://www.youtube.com/watch?v=E09p94G2fv8 If anyone wants to see Bob Odenkirk's first stab at an action role, like 11 or 12 years before Nobody, here ya go.
Have you thought about what happens if we don't find a way out of here?
ADAM SCOTT as MAGICIAN | Operation: Endgame — 2010

Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
Free to watch • No registration required • HD streaming
Far more talent is on display in front of the camera than behind it during the frequently gender-mixed throw downs that comprise the bulk of the picture. Emilie de Ravin (Lost) is brimming with psychosis as Heirophant, more than holding her own against Ving Rhames' Judgement.
http://exclaim.ca/film/article/operation_endgame-directed_by_fouad_mikati
The Hierophant x Father Joseph MacAvoy -
"A-are ye nae listening to me, I-I'm nae okay!" - Joseph
"Uh-huh...I heard ya'the first time sweetheart." - Hiero
Father MacAvoy - The Hierophant - Colonel Ives