Police raid malware network tied to Russia's Evil Corp hacker group

2026-06-20T02:51:53Z73598a1c3f411aec6f6484ece1a1c35b77375bde1c8e7bc90d0f83d0c5631d92
Evil CorpRussiaSocGholishbotnetcybercrimedisruptioninternational law enforcementmalwareransomwaretakedown

What happened

International law-enforcement agencies carried out an operation that disrupted the SocGholish browser-injection botnet, a malware distribution infrastructure tied to the Russia-based cybercrime group Evil Corp. The action targeted command-and-control and affiliate infrastructure, reducing immediate deployment capability, but residual infections and rapid reconstitution or pivot to other distribution channels remain possible. Monitor for follow-on activity (ransomware/extortion campaigns, renewed phishing) and for seized infrastructure being replaced or abused by other operators.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
73598a1c3f411aec6f6484ece1a1c35b77375bde1c8e7bc90d0f83d0c5631d92
Enrichment time
2026-06-20T02:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.