
14,971 WordPress Sites Cleaned as Operation Endgame Disrupts SocGholish Servers
A coordinated takedown removes malicious scripts from thousands of hacked WordPress sites and disrupts servers used by SocGholish, a threat known for fake browser update scams.
A coordinated security operation named Operation Endgame has disrupted servers tied to SocGholish malware and cleaned malicious code from 14,971 WordPress websites. SocGholish is a long-running threat that uses compromised websites, many of them running WordPress, to trick visitors into downloading harmful software. The action removes a significant source of fake browser update scams that have affected countless internet users.
SocGholish typically works by first breaking into a vulnerable WordPress site. Attackers look for outdated plugins, themes, or weak login credentials, which are the username and password used to manage the site. Once inside, they inject a small piece of JavaScript, a type of code that runs inside a visitor's web browser. When someone visits the infected page, that code triggers a realistic-looking alert claiming that the visitor's Chrome, Firefox, or Edge browser needs an urgent update. If the visitor clicks the download button, they receive a remote access trojan, which is malware that lets an attacker quietly control the victim's computer from far away, or information-stealing malware that collects passwords and other private data. This can give attackers a foothold on the victim's computer, allowing them to steal banking details or even hold files for ransom.
Operation Endgame's latest action takes down the command-and-control servers, the computers used by attackers to send instructions to infected machines. These servers manage SocGholish infections and deliver the final malware payload. Without them, fake update redirects often fail, and existing infections lose their ability to receive new instructions. At the same time, the operation cleaned 14,971 WordPress sites by removing the malicious script injections. This is important because many site owners were unaware their websites had been hijacked. Visitors to those sites were being exposed to the fake update scam every day. Removing the injected code protects both the site owners and their visitors from further harm.
The cleanup does not mean those WordPress sites were permanently fixed against future attacks. Site owners still need to address the root cause, often an outdated plugin or a weak password. They should update WordPress core, plugins, and themes, use strong unique passwords, enable two-factor authentication where possible, which is a security step that requires a second proof of identity like a code from a phone, and regularly scan their files for unexpected changes. For everyday internet users, the most important defence is to never download a browser update from a pop-up window. Real browser updates come through the browser's own settings menu or the official app store, not from a website you were just visiting.
For businesses and website owners, prevention means keeping WordPress fully updated, using strong unique passwords, enabling two-factor authentication, and regularly reviewing installed plugins. Managed WordPress hosting that includes end-to-end security, such as AEU Hosting, can make it much harder for attackers to inject SocGholish-type scripts in the first place.
How to Protect Yourself
- If a website you visit suddenly shows a pop-up telling you to update your web browser, close that pop-up and update your browser only through its official settings menu.
- Keep your WordPress website, themes, and plugins updated to the latest versions as soon as updates are available.
- Use a strong, unique password for your WordPress admin account and turn on two-factor authentication (a second login step like a code from your phone) if your hosting provider offers it.
- Regularly scan your website files for unexpected changes using a security plugin or ask your hosting provider about malware scanning.
- Back up your website regularly so that if it gets hacked, you can restore a clean copy quickly.