SocGholish
MITRE ATT&CK: S1124 View on attack.mitre.org
Aliases: FakeUpdates, FakeUpdate, GhoLoader, SocGholish
- First seen
- 2017-01-01 00:00:00
- Malware type
- loader, downloader
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 1856 (1341 malicious)
- Last IoC activity
- 2026-09-02 04:13:52
- Profile updated
- 2026-07-07 13:02:42
Targeted industries: government-and-public-sector technology-and-telecommunications media-and-entertainment financial-services
Context
SocGholish is a JavaScript-based loader malware that has been used since at least 2017. It has been observed in use against multiple sectors globally for initial access, primarily through drive-by-downloads masquerading as software updates. SocGholish is operated by Mustard Tempest and its access has been sold to groups including Indrik Spider for downloading secondary RAT and ransomware payloads.
Recent IoC activity
1,348 malicious indicators in Maltiverse are attributed to SocGholish (S1124). The 20 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 198.98.59.241 | 2026-09-03 | 6 |
| hostname | app-api.starfoodmart.net | 2026-09-03 | 1 |
| hostname | images.miamionly.com | 2026-09-03 | 1 |
| hostname | funcallback.com | 2026-09-03 | 1 |
| hostname | secure.happyhatterreviews.com | 2026-09-03 | 1 |
| hostname | whizability.com | 2026-09-03 | 1 |
| hostname | restbycalm.com | 2026-09-03 | 1 |
| hostname | ibm.deltavis.net | 2026-09-03 | 1 |
| hostname | progress.moneymatrixonline.com | 2026-09-03 | 1 |
| hostname | linedloop.org | 2026-09-03 | 3 |
| hostname | gtpsostaric.com | 2026-09-03 | 1 |
| hostname | ecoterica.com | 2026-09-03 | 1 |
| hostname | minjeff.com | 2026-09-03 | 1 |
| hostname | kuishang.top | 2026-09-03 | 1 |
| hostname | 99wc.top | 2026-09-03 | 1 |
| hostname | foodiepharm.com | 2026-09-03 | 1 |
| hostname | ashleypuerner.com | 2026-09-03 | 1 |
| hostname | static.theellsworths.uk | 2026-09-03 | 1 |
| hostname | client.assuredpestcontrolutah.com | 2026-09-03 | 1 |
| hostname | order.meetandeatsac.com | 2026-09-03 | 1 |
Detection coverage
- 2 YARA rules
- 284 Sigma rules
Malware & tools used
- System Information Discovery (attack-pattern)
- System Location Discovery (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Domain Trust Discovery (attack-pattern)
- JavaScript (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Spearphishing Link (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Malicious Link (attack-pattern)
- Software Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Local Data Staging (attack-pattern)
- Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
- Web Service (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Compression (attack-pattern)
Used by threat actors
- Mustard Tempest (threat-actor)
Detection rules
- SIGNATURE_BASE_EXT_MAL_JS_Socgholish_Mar21_1 (yara-rule)
- SIGNATURE_BASE_Socgholish_JS_22_02_2022 (yara-rule)
Reports & references
- Microsoft — Ransomware As A Service Understanding The Cybercrime Gig Economy And How To Protect Yourself (report)
- secureworks.com — Gold Prelude (report)
- Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
- services.google.com — Threat Horizons Report H1 2025 (report)
- recordedfuture.com — Uncovering Mintsloader With Recorded Future Malware Intelligence Hunting (report)
- proofpoint.com — Part 1 Socgholish Very Real Threat Very Fake Update (report)
- killingthebear.jorgetesta.tech — Evil Corp (report)
- Mandiant — Unc2165 Shifts To Evade Sanctions (report)
- Microsoft — Raspberry Robin Worm Part Of Larger Ecosystem Facilitating Pre Ransomware Activity (report)
- research.nccgroup.com — Back In Black Unlocking A Lockbit 3 0 Ransomware Attack (report)
- twitter.com — 1522690116979855360 (report)
- Trend Micro — Iocs Thwarting Loaders Socgholish Blister.Txt (report)
- Trend Micro — Thwarting Loaders From Socgholish To Blisters Lockbit Payload (report)
- intrinsec.com — Tlp Clear Prospero Proton66 Uncovering The Links Between Bulletproof Networks (report)
- info.spamhaus.com — Jul Dec%202024%20Botnet%20Threat%20Update (report)
- intrinsec.com — Prospero Proton66 Tracing Uncovering The Links Between Bulletproof Networks (report)
- info.spamhaus.com — Jan Jun%202024%20Botnet%20Threat%20Update (report)
- info.spamhaus.com — Q4%202023%20Botnet%20Threat%20Update (report)
- proofpoint.com — Update Fake Updates Two New Actors And New Mac Malware (report)
- Mandiant — 1 (report)
- blog.morphisec.com — Coinlurker The Stealer Powering The Next Generation Of Fake Updates (report)
- malpedia.caad.fkie.fraunhofer.de — Js.Fakeupdates (report)
- proofpoint.com — Ta569 Socgholish And Beyond (report)
- intrinsec.com — Tlp Clear Matanbuchus Co Code Emulation And Cybercrime Infrastructure Discovery 1 (report)
- rapid7.com — Fake Update Utilizes New Idat Loader To Execute Stealc And Lumma Infostealers (report)
External references
- mitre-attack — S1124
- FakeUpdates
- SocGholish-update
- SentinelOne SocGholish Infrastructure November 2022
- Red Canary SocGholish March 2024
- Secureworks Gold Prelude Profile
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy