Skip to content
Back to the blog
Malware June 22, 2026

“Operation Endgame” dismantles SocGholish and cleans almost 15,000 WordPress sites

In mid-June 2026, an international coalition of police forces coordinated by Europol dealt a major blow to one of the longest-running malware distribution systems on the internet. As part of “Operation Endgame”, the authorities took down 106 malicious servers and domains and cleaned 14,971 compromised WordPress websites without their owners knowing. The culprit is SocGholish (also known as FakeUpdates), a malware downloader active since 2017 that hijacks legitimate pages and injects code that shows visitors a fake “browser update” notice. If the visitor downloads that supposed patch, they actually install malicious software on their computer.

The seriousness lies in what comes next: SocGholish has been used for years as a gateway to deploy highly damaging ransomware. For an SME or a freelancer the risk is twofold. On the one hand, if your WordPress site is infected, your business unknowingly becomes bait to deceive your own customers, damaging your reputation. On the other, as an ordinary internet user, simply visiting a trusted website that has been compromised and falling for the fake update notice is enough to end up with your computer held hostage by ransomware.

Tip from Soporte Informático 360

If you manage a WordPress site, enable MFA on administrator accounts and always keep the core, plugins and themes up to date. And remember a golden rule: browsers are never updated through a pop-up window inside a web page; if you see one of those notices, close it and update from the browser’s own menu.

Source: The Hacker News. Summary prepared by our team for informational purposes.

Do you think a device may be compromised?

We help you check it, clean it and protect it. Write to us with no obligation.

Get help