Operation Endgame Sweep Takes Down SocGholish Loader Infrastructure

Dutch-led coalition disrupts servers and remediates 14,971 compromised WordPress sites, in the latest tranche of the multinational takedown effort.

ThreatVectr Newsdesk· 2 min read
Operation Endgame Sweep Takes Down SocGholish Loader Infrastructure
Share

Dutch law enforcement, working alongside agencies in Canada, Germany, and the United States, has dismantled command-and-control infrastructure tied to the SocGholish loader and remediated nearly 15,000 compromised WordPress sites used to deliver it.

The action falls under the umbrella of Operation Endgame, the recurring multi-jurisdictional sweep first announced in May 2024.

SocGholish — sometimes tracked as FakeUpdates — is a JavaScript-based downloader operated by the actor Mandiant designates UNC1543 and others track as TA569. It seeds compromised legitimate websites with fake browser-update lures, then hands off to ransomware affiliates and access brokers further down the chain.

The Netherlands National High Tech Crime Unit (NHTCU) confirmed the disruption in a statement attributed to officer Maikel Rollman. "With these actions we deprive cybercriminals of access to infected computer systems," Rollman said. "This prevents" further victim impact, per the partial readout released by Dutch authorities.

The operation targeted 14,971 WordPress installations that had been wedged into the SocGholish delivery network. Authorities indicate the affected hosts have been cleaned, though the legal authority cited for the cleanup — and whether site owners were notified before remediation — was not detailed in the public announcement.

That distinction matters.

U.S. takedowns of botnet infrastructure increasingly rely on court-authorized remote access under Rule 41 of the Federal Rules of Criminal Procedure, while European partners typically operate under domestic computer-crime statutes and EU mutual legal assistance frameworks. The participating agencies have not yet published the underlying seizure orders or affidavits.

SocGholish has been a persistent feeder into ransomware ecosystems. Prior incident response reporting has linked it to Evil Corp, LockBit affiliates, and RansomHub deployments. Disrupting the loader layer, rather than the ransomware brand itself, reflects the strategy Europol has signaled across the Endgame cycles: degrade the access economy upstream of encryption events.

No arrests were announced in connection with this phase. Operation Endgame's prior rounds, in May 2024 and May 2025, produced seizures against IcedID, SystemBC, Pikabot, Smokeloader, Bumblebee, and DanaBot infrastructure, alongside indictments unsealed by the U.S. Department of Justice.

WordPress site operators should treat the cleanup as a starting point, not a closure. Compromised sites typically retain backdoored plugins, modified theme files, or rogue administrator accounts that survive the removal of the initial injection. CISA's guidance on web shell detection and the WordPress core hardening recommendations remain the relevant baselines.

Expect a fuller Europol readout in the coming days. The participating prosecutors' offices — including the Netherlands Public Prosecution Service and the U.S. Attorney's Office handling the American component — typically release charging documents or seizure notices on a staggered timeline after the operational phase concludes.

© 2026 Threat Vectr