SocGholish uses traffic distribution systems (TDSs) to provide initial access into victims' networks for cybercrime groups such as the notorious Evil Corp.
June 23, 2026
An international law enforcement operation disrupted a key cog in the cybercrime ecosystem and put a spotlight on the risks to enterprises posed by traffic distribution systems (TDSs).
In the latest installment of the ongoing Operation Endgame, authorities seized 106 servers and many domains tied to SocGholish, a notorious malware framework that has plagued the Internet for nearly a decade as an initial-access broker for ransomware and other threats. The law-enforcement operation also remediated 14,971 websites, primarily hosted on WordPress, that had been compromised by SocGholish operators.
According to the Netherlands' National Police Corps, SocGholish is "a key infection chain" used by many cybercriminal gangs, most notably the Russian ransomware gang Evil Corp. The multi-stage JavaScript malware is injected through compromised websites and appear as fake browser updates.











