Description
Trojan.FakeUpdater (a.k.a. SocGholish) is a JavaScript downloader that impersonates browser update prompts to deliver payloads such as Dridex and Azorult. Cyberattackers inject the script into compromised websites, so visitors encounter the fake update dialog while browsing normally, and users who follow its instructions execute the downloader directly. The family feeds established criminal ecosystems, and its low friction social engineering makes it one of the most successful web-based delivery frameworks.
Stats
- First seen
- September 2022
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| Document-HTML.Malware.FakeUpdater |
| Document-HTML.Trojan.FakeUpdater |
| MacOS.Trojan.FakeUpdater |
| Script-JS.Dropper.FakeUpdater |
| Script-JS.Trojan.FakeUpdater |
| Script.Trojan.FakeUpdater |
| Text.Trojan.FakeUpdater |
| Win32.Trojan.FakeUpdater |