SocGholish
Description
(Menlo Labs) The term “Soc” in the “SocGholish” framework refers to the attack’s use of social engineering toolkits masquerading as a software update. Thus far, Menlo has observed this particular framework using several social engineering themes that impersonate browser updates (Chrome/Firefox), Flash Player updates, and more recently, Microsoft Teams updates.
Names
Name |
---|
SocGholish |
FAKEUPDATES |
FakeUpdate |
Category
Malware
Type
- Downloader
Information
- https://www.menlosecurity.com/blog/increase-in-attack-socgholish
- https://blog.truesec.com/2021/05/05/are-the-notorious-cyber-criminals-evil-corp-actually-russian-spies/
- https://isc.sans.edu/forums/diary/Fake+browser+update+pages+are+still+a+thing/25774/
- https://www.trendmicro.com/en_us/research/22/d/Thwarting-Loaders-From-SocGholish-to-BLISTERs-LockBit-Payload.html
- https://www.cybereason.com/blog/threat-analysis-report-socgholish-and-zloader-from-fake-updates-and-installers-to-owning-your-systems
- https://blog.sucuri.net/2022/08/socgholish-5-years-of-massive-website-infections.html
- https://www.malwarebytes.com/blog/news/2024/12/malicious-ad-distributes-socgholish-malware-to-kaiser-permanente-employees
Mitre Attack
Malpedia
Other Information
Uuid
9da2592e-91a9-4ee1-a05e-fe50fb16bffe
Last Card Change
2024-12-27