1 min read
Russian GRU Targeting Western Logistics Entities and Technology Companies
Originally Published June 26, 2025
5 min read
Cyber Florida SOCAP Team
:
Updated on August 17, 2026
Originally published: 11/25/2024
According to The Multi-State Information Sharing and Analysis Center’s (MS-ISAC) monitoring services, SocGholish has retained its position as the most prevalent malware in Q3 2024, accounting for 42% of observed infections. SocGholish is a JavaScript-based downloader that spreads primarily through malicious or compromised websites that present fake browser update prompts to users. Once deployed, SocGholish infections can facilitate further exploitation by delivering additional malicious payloads.
SocGholish, also known as “FakeUpdates,” has emerged as the leading malware in Q3 2024. This malware has been active since 2018 and operates as a JavaScript-based downloader that exploits drive-by-download techniques to gain initial access. SocGholish primarily spreads through compromised websites, which present fake browser or software update prompts to unsuspecting users. When users download and run the updates, they execute a malicious payload that establishes communication with SocGholish’s command-and-control (C2) infrastructure.
The malware typically delivers its payload via direct download of JavaScript files or, less frequently, within obfuscated ZIP archives to evade detection. The attackers have continued to adapt, using techniques such as homoglyphs in filenames to bypass string-based detection methods. Once deployed, SocGholish conducts reconnaissance on infected systems, identifying users, endpoints, and potentially critical assets such as Active Directory domains. In about 10% of cases, the malware escalates to delivering second-stage payloads, including remote access tools (RATs) like Mythic, replacing previously popular choices like NetSupport.
SocGholish serves as an initial access broker, facilitating further exploitation by delivering additional malware, including ransomware variants such as LockBit and WastedLocker. Its activities often serve as precursors to larger attacks, making it a critical threat to monitor. Infections may involve domain trust enumeration and script-based data exfiltration, primarily executed in memory, complicating detection efforts. Organizations are advised to implement preventive measures, such as disabling automatic JavaScript execution, monitoring for unusual script activity, and swiftly isolating infected hosts to mitigate the impact of potential intrusions.
| Type | Indicator |
|---|---|
| IP |
83[.]69[.]236[.]128 |
| IP |
88[.]119[.]169[.]108 |
| IP |
91[.]121[.]240[.]104 |
| IP | 185[.]158[.]251[.]240 |
| IP | 185[.]196[.]9[.]156 |
| IP | 193[.]233[.]140[.]136 |
| IP | 31.184.254[.]115 |
| Domain | aitcaid[.]com |
| Domain | 0qsc137p[@]justdefinition.com |
| Domain | advancedsportsandspine[.]com |
| Domain | automotivemuseumguide[.]com |
| Domain | brow-ser-update[.]top |
| Domain | circle[.]innovativecsportal[.]com |
| Domain | marvin-occentus[.]net |
| Domain | photoshop-adobe[.]shop |
| Domain | pluralism[.]themancav[.]com |
| Domain | scada.paradizeconstruction[.]com |
| Domain | storefixturesandsupplies[.]com |
| Domain | 1sale[.]com |
| Domain | taxes.rpacx[.]com |
| Domain | *.signing.unitynotarypublic[.]com |
| Domain | *.asset.tradingvein[.]xyz |
| Domain | Column 2 Value 23 |
| Domain | change-land[.]com |
SocGholish operates as a JavaScript-based malware loader that initially infects victims through compromised websites, presenting them with fake browser or software update prompts. Once users click “update,” the malware executes a JavaScript payload that connects back to the attacker’s command-and-control (C2) server to deliver additional payloads.
Payload details:
By delivering these targeted payloads, SocGholish operators can gain persistent access, conduct extensive reconnaissance, and potentially disrupt critical systems. These payloads make SocGholish not only a potent malware threat but also a significant enabler of larger ransomware and espionage campaigns across various industries.
The Center for Internet Security, Inc (October 23, 2024). Top 10 Malware Q3 2024 https://www.cisecurity.org/insights/blog/top-10-malware-q3-2024
Red Canary (2024) SocGholish https://redcanary.com/threat-detection-report/threats/socgholish/
MITRE ATT&CK (March 22, 2024) SocGholish https://attack.mitre.org/software/S1124/
Blackpoint Cyber (June 21, 2024) AsyncRAT, NetSupport RAT, and VssAdmin Abuse for Shadow Copy Deletion https://blackpointcyber.com/resources/blog/asyncrat-netsupportrat-vssadmin-abuse-for-shadow-copy-deletion-soc-incidents-blackpoint-apg/
Proofpoint (November 22, 2022) Part 1: SocGholish, a very real threat from a very fake update https://www.proofpoint.com/us/blog/threat-insight/part-1-socgholish-very-real-threat-very-fake-update
ReliaQuest (January 30, 2023) SocGholish: A Tale of FakeUpdates https://www.reliaquest.com/blog/socgholish-fakeupdates/
Contributing Security Analysts: Yousef Blassy, Uday Bilakhiya, Thiago Pagliaroni, and Kayla Walker.
1 min read
Originally Published June 26, 2025
1 min read
Originally published: 12/03/2024 I. Targeted Entities Internet users II. Introduction LandUpdate808 is a malicious downloader that distributes...
1 min read
Published 03/10/2023 I. Targeted Entities Opportunistic (any industry) II. Introduction RedLine Stealer is a malware family written in C# that...