SocGholish

THREAT ACTOR PROFILE

SocGholish

SocGholish

SocGholish

Mustard Tempest

SocGholish is a long-running malware-as-a-service operation run by TA569 that uses fake browser-update lures on compromised websites to deliver a JScript stager. It sells the resulting access to other criminals, acting as a major initial-access broker feeding ransomware affiliates. A 2026 Operation Endgame action disrupted its infrastructure but did not end the operation.

Not attributed

Malware-as-a-service / Access broker

First seen

2017

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

SocGholish, TA569 and Mustard Tempest

SocGholish is tracked under several names tied to its operator and campaign. It maps to one entry among the malware-as-a-service operators we track, and its access-broker role feeds affiliates like RansomHub.

-

-

-

GROUP PROFILE

Fake updates as an access-broker business

SocGholish is a malware-as-a-service vendor. It compromises legitimate websites, serves fake browser-update prompts, and uses the resulting foothold to deliver follow-on malware for paying clients, functioning as one of the most prolific initial-access operations.

Our record ties it to fake-update drive-by activity and access brokering. Operation Endgame, led by law enforcement in the Netherlands, Canada, the US and Germany with Europol, took down over 100 servers and domains and remediated nearly 15,000 compromised WordPress sites.

The group runs a traffic distribution system and web injects on compromised sites, delivering a small JScript stager (FAKEUPDATES) that leads to loaders, stealers and, downstream, ransomware.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

ATTACK LIFECYCLE

Compromised sites and fake updates into follow-on malware

The stages below come from SocGholish and TA569 activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

FAKEUPDATES, GhostWeaver and a loader ecosystem

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Access through fake updates, not CVE exploitation

SocGholish gains initial access through fake browser-update social engineering on compromised sites rather than through exploiting a consistent set of software vulnerabilities, so this profile does not list a confirmed exploited-CVE set for its own intrusions. Detection should focus on the FAKEUPDATES JScript stager and the compromised-site traffic distribution system.

SocGholish

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

SocGholish

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

SocGholish

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

SocGholish

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

Operation Endgame and the fake-update ecosystem

Recent reporting tracks the law-enforcement disruption and the group's tooling.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

SocGholish

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

SocGholish

IOC set, full IP, host and hash history.