SocGholish Campaign Targeting Compromised WordPress Sites

Release Date: 18th June 2026

Impact : HIGH / CRITICAL

TLP Rating: Clear

The Department of Communication and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above products. This alert is intended to be understood by technical users and systems administrators.

What is it?

CERT Vanuatu advises on SocGholish (also known as FakeUpdates, DEV-0206, TA569, GOLD PRELUDE, Mustard Tempest, and UNC1543) is a malware delivery framework that compromises legitimate WordPress websites and uses them to distribute malware through fake browser or software update prompts. Rather than exploiting visitors directly through a software vulnerability, attackers first compromise WordPress sites and inject malicious code that redirects users to attacker-controlled infrastructure.

According to a recent report by the Shadowserver Foundation, law enforcement and industry partners disrupted a major SocGholish operation, remediating 14,971 compromised WordPress sites and taking down 106 malicious servers and domains.

 

References

  1. https://www.shadowserver.org/news/socgholish-compromised-wordpress-sites-special-report/
  2. https://redcanary.com/threat-detection-report/threats/socgholish/
  3. https://cyberscoop.com/socgholish-malware-botnet-takedown-evilcorp/
  4. https://www.motorolasolutions.com/en_us/blog/detecting-early-stage-socgholish-attack