Operation Endgame Cleans 14,971 Infected WordPress Sites Worldwide
An international police operation, part of 'Operation Endgame,' has dismantled a Russian-linked cybercrime network, cleaning nearly 15,000 infected WordPress sites globally.
Intelligence analysis by Gemini 2.5 Flash

Law enforcement agencies worldwide, supported by Europol and Eurojust, targeted the SocGholish malware framework, linked to the notorious Evil Corp group. This network tricked users into downloading malicious files disguised as legitimate updates, exploiting WordPress vulnerabilities to gain unauthorized access to systems.
Imagine bad guys trying to sneak into your computer by pretending to be a software update for your web browser. They trick websites into showing these fake updates, and if you click, they install secret software that lets them steal your information. Police from many countries worked together to shut down thousands of these sneaky websites, like closing many doors the bad guys used to get in.
Analysis
A Coordinated Global Takedown
Operation Endgame represents a significant victory in the ongoing battle against sophisticated cybercrime. This international police effort, involving multiple countries with support from Europol and Eurojust, successfully disrupted a vast Russian-linked cybercrime network. The scale of the operation is notable, resulting in the cleanup of 14,971 compromised WordPress websites and the takedown of 106 servers and domains. This coordinated action effectively deprives cybercriminals of their infrastructure, preventing further damage and reducing the risk of future attacks on critical infrastructure globally.
Unmasking Evil Corp's Tactics
The primary target of this operation was the SocGholish malware framework, which authorities have linked to Evil Corp, a Russian cybercriminal group active since 2017. Evil Corp's modus operandi involves tricking users into downloading malicious files disguised as legitimate computer updates, a technique security researchers call a ClickFix-style attack. The malware spread through thousands of compromised WordPress sites, exploiting known vulnerabilities or stolen credentials to gain unauthorized access. The group has a history of deploying various banking trojans like Zeus and Dridex, and has been associated with major ransomware operations including WastedLocker, LockBit, and RansomHub, underscoring its long-standing and diverse threat profile. British law enforcement has even connected Evil Corp to Russian intelligence, suggesting state-sponsored cyberattacks and espionage.
Sustaining Digital Defenses
The success of Operation Endgame provides a temporary reprieve but also serves as a stark reminder of the persistent threat posed by cybercriminal organizations. While the immediate impact is positive, the underlying vulnerabilities and human factors that enable such attacks remain. Authorities are urging WordPress site owners to take proactive measures, including changing login credentials, enabling multi-factor authentication, deleting unrecognized accounts, and keeping their sites fully updated. These steps are vital to prevent reinfection and bolster overall digital security, ensuring that the gains from this operation are not quickly undone by complacency or neglect.
Key points
- Operation Endgame, an international police effort, disrupted a Russian-linked cybercrime network.
- The operation cleaned 14,971 WordPress sites infected with SocGholish malware and took 106 servers/domains offline.
- SocGholish is linked to Evil Corp, a group known for fake browser updates and ties to banking trojans and ransomware.
- Evil Corp has been connected to Russian intelligence, tasked with cyberattacks and cyberespionage.
- Authorities urge WordPress site owners to update credentials, enable multi-factor authentication, and keep sites updated to prevent reinfection.
The successful disruption of this major cybercrime network significantly reduces the immediate threat of SocGholish malware, protecting thousands of websites and users from data theft and system compromise. This coordinated international effort demonstrates the growing capability of law enforcement to combat sophisticated online threats, fostering a safer digital environment.
Despite this significant takedown, the underlying vulnerabilities in WordPress and the persistent nature of cybercrime mean that new threats or a resurgence of similar operations are likely. Users and website owners must remain vigilant, as cybercriminals constantly evolve their tactics, requiring continuous updates and security measures to prevent reinfection.



