Description
SocGholish (a.k.a. FakeUpdater) is a JavaScript based malware delivery framework that impersonates browser update prompts to trick visitors of compromised websites into running its downloader. Users encounter the fake update dialog during normal browsing, and the script fetches payloads such as Dridex, Azorult, and remote access tools for downstream crews. Its access to legitimate web traffic has made it a leading initial access broker for ransomware operations.
Stats
- First seen
- April 2022
- Last seen
- October 2026
Also known as
FakeUpdatesSocgholish
MITRE ATT&CK techniques
19 techniques across 7 tactics.
TA0002 Execution
TA0005 Stealth
TA0007 Discovery
Associated groups
Alert name variants
| Alert Name |
|---|
| Document-HTML.Dropper.SocGholish |
| Document-HTML.Malware.SocGholish |
| Document-HTML.Trojan.SocGholish |
| Package.Trojan.FakeUpdates |
| Script-JS.Downloader.FakeUpdates |
| Script-JS.Malware.SocGholish |
| Script-JS.Trojan.FakeUpdates |
| Script-JS.Trojan.Socgholish |
| Script-JS.Trojan.SocGholish |
| Script.Trojan.SocGholish |
Related IPS Signatures
| Signature Name |
|---|
| MALWARE-CNC UNC1543.FAKEUPDATES C2 check-in detected |