SocGholish

MITRE ATT&CK: S1124 View on attack.mitre.org

Aliases: FakeUpdates, FakeUpdate, GhoLoader, SocGholish

First seen
2017-01-01 00:00:00
Malware type
loader, downloader
Family
Malware family
Operating systems
windows
Related IoCs
1856 (1341 malicious)
Last IoC activity
2026-09-02 04:13:52
Profile updated
2026-07-07 13:02:42

Targeted industries: government-and-public-sector technology-and-telecommunications media-and-entertainment financial-services

Context

SocGholish is a JavaScript-based loader malware that has been used since at least 2017. It has been observed in use against multiple sectors globally for initial access, primarily through drive-by-downloads masquerading as software updates. SocGholish is operated by Mustard Tempest and its access has been sold to groups including Indrik Spider for downloading secondary RAT and ransomware payloads.

Recent IoC activity

1,348 malicious indicators in Maltiverse are attributed to SocGholish (S1124). The 20 most recently updated:

TypeIndicatorUpdatedSources
IP address 198.98.59.241 2026-09-03 6
hostname app-api.starfoodmart.net 2026-09-03 1
hostname images.miamionly.com 2026-09-03 1
hostname funcallback.com 2026-09-03 1
hostname secure.happyhatterreviews.com 2026-09-03 1
hostname whizability.com 2026-09-03 1
hostname restbycalm.com 2026-09-03 1
hostname ibm.deltavis.net 2026-09-03 1
hostname progress.moneymatrixonline.com 2026-09-03 1
hostname linedloop.org 2026-09-03 3
hostname gtpsostaric.com 2026-09-03 1
hostname ecoterica.com 2026-09-03 1
hostname minjeff.com 2026-09-03 1
hostname kuishang.top 2026-09-03 1
hostname 99wc.top 2026-09-03 1
hostname foodiepharm.com 2026-09-03 1
hostname ashleypuerner.com 2026-09-03 1
hostname static.theellsworths.uk 2026-09-03 1
hostname client.assuredpestcontrolutah.com 2026-09-03 1
hostname order.meetandeatsac.com 2026-09-03 1

Detection coverage

  • 2 YARA rules
  • 284 Sigma rules

Malware & tools used

  • System Information Discovery (attack-pattern)
  • System Location Discovery (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Domain Trust Discovery (attack-pattern)
  • JavaScript (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Malicious Link (attack-pattern)
  • Software Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • Web Service (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Compression (attack-pattern)

Used by threat actors

Detection rules

  • SIGNATURE_BASE_EXT_MAL_JS_Socgholish_Mar21_1 (yara-rule)
  • SIGNATURE_BASE_Socgholish_JS_22_02_2022 (yara-rule)

Reports & references

  • Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
  • secureworks.com — Gold Prelude (report)
  • Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
  • services.google.com — Threat Horizons Report H1 2025 (report)
  • recordedfuture.com — Uncovering Mintsloader With Recorded Future Malware Intelligence Hunting (report)
  • proofpoint.com — Part 1 Socgholish Very Real Threat Very Fake Update (report)
  • killingthebear.jorgetesta.tech — Evil Corp (report)
  • Mandiant — Unc2165 Shifts To Evade Sanctions (report)
  • Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
  • research.nccgroup.com — Back In Black Unlocking A Lockbit 3 0 Ransomware Attack (report)
  • twitter.com — 1522690116979855360 (report)
  • Trend Micro — Iocs Thwarting Loaders Socgholish Blister.Txt (report)
  • Trend Micro — Thwarting Loaders From Socgholish To Blisters Lockbit Payload (report)
  • intrinsec.com — Tlp Clear Prospero Proton66 Uncovering The Links Between Bulletproof Networks (report)
  • info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
  • intrinsec.com — Prospero Proton66 Tracing Uncovering The Links Between Bulletproof Networks (report)
  • info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
  • info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
  • proofpoint.com — Update Fake Updates Two New Actors And New Mac Malware (report)
  • Mandiant — 1 (report)
  • blog.morphisec.com — Coinlurker The Stealer Powering The Next Generation Of Fake Updates (report)
  • malpedia.caad.fkie.fraunhofer.de — Js.Fakeupdates (report)
  • proofpoint.com — Ta569 Socgholish And Beyond (report)
  • intrinsec.com — Tlp Clear Matanbuchus Co Code Emulation And Cybercrime Infrastructure Discovery 1 (report)
  • rapid7.com — Fake Update Utilizes New Idat Loader To Execute Stealc And Lumma Infostealers (report)

External references