:

LAW ENFORCEMENT TAKES DOWN 15,000 SOCGHOLISH-INFECTED SITES

INDUSTRY DESK1 MIN READ
THU, JUN 18, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

International police agencies have dismantled nearly 15,000 WordPress websites infected with SocGholish malware and shut down over 100 servers connected to Evil Corp, a Russian cybercrime group.

The coordinated operation targeted the SocGholish botnet, a malware distribution network primarily used for credential theft and ransomware deployment. Evil Corp, also known as WIZARD SPIDER, has been linked to major ransomware campaigns affecting critical infrastructure and businesses worldwide. Authorities cleaned the compromised WordPress installations and seized infrastructure used to command and control the botnet. The takedown represents a significant disruption to one of Russia's most active cybercriminal operations. Evil Corp has been sanctioned by the U.S. Treasury Department and is known for developing the Dridex banking trojan and operating the Conti ransomware-as-a-service platform. The group has targeted healthcare systems, financial institutions, and government agencies across multiple countries. The operation involved law enforcement from multiple nations and coordination with hosting providers to identify and remediate infected systems.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Let's Encrypt experienced widespread certificate renewal failures today, according to the service status page. The incident affected numerous users attempting to renew their SSL certificates.

2H AGOIndustry Desk

Microsoft has identified a lightweight backdoor malware that targets cryptocurrency wallets and spreads via USB drives. The malware, known as Crypto Clipper, communicates through the Tor network to evade detection.

2H AGOIndustry Desk

India's government told the Delhi High Court that Telegram acknowledged its inability to proactively detect channels selling leaked exam papers. The platform was warned two weeks before being blocked in the country.

7H AGOIndustry Desk

Australia's communications regulator will require businesses to register their SMS and MMS sender identities. The move aims to combat spam and fraudulent messaging.

7H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.