Police raid malware network tied to Russia's Evil Corp hacker group

2026-06-21T02:51:53Z7f1eaed3f0a5ce3058225395e1bd6c47ae71029b063c41977ab22ea12babb535
Evil CorpSocGholishbotnet takedownbrowser-based malwarecybercrimedisruptioninitial accessinternational operationlaw enforcement operationmalvertisingransomwarethreat actor

What happened

International law-enforcement agencies disrupted the SocGholish botnet, which has been linked to the Russia-based cybercrime group Evil Corp. SocGholish is a browser-based malvertising/drive-by infection framework historically used to deliver loaders and follow-on payloads (including ransomware and other loaders used by criminal groups). The takedown disrupts active infrastructure but does not eliminate the threat—Evil Corp affiliates and other operators can pivot to alternative initial-access vectors or rebuild infrastructure. Organizations should treat this as a temporary reduction in risk,増

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
7f1eaed3f0a5ce3058225395e1bd6c47ae71029b063c41977ab22ea12babb535
Enrichment time
2026-06-21T02:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.