Police raid malware network tied to Russia's Evil Corp hacker group

2026-06-21T08:52:03Z07d015c502a97cc5567dd7b0fb00bc26e29416e6fdd87533de64984dfed93f88
Evil CorpRussiaSocGholishbotnet takedowncybercrimeinternational law enforcementmalware distributionmalware loaderthreat disruption

What happened

An international law-enforcement operation disrupted the SocGholish browser-based botnet on 19 Jun 2026. SocGholish has been used as a loader/redirector to deliver a range of malware and has been linked to the Russia-based cybercrime group Evil Corp; dismantling its infrastructure will reduce immediate distribution but affiliates and fallback domains/servers may persist. Organizations should monitor for SocGholish IOCs and domains, review email and web-proxy detections, apply browser and OS patches, and update endpoint protections to detect post-exploitation activity.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
07d015c502a97cc5567dd7b0fb00bc26e29416e6fdd87533de64984dfed93f88
Enrichment time
2026-06-21T08:52:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.