Police raid malware network tied to Russia's Evil Corp hacker group

2026-06-21T20:51:53Z8e03f0d5d464a0520d7e1c5c46a252dba2ebad3f85ae42d04a0e70b562a3bc90
Evil CorpSocGholishbotnetcybercrimeinternational operationlaw enforcementmalvertisingmalwareransomwaretakedown

What happened

International law enforcement conducted a coordinated operation that disrupted the SocGholish malvertising/botnet infrastructure tied to the Russia-based cybercrime group Evil Corp. The takedown targeted servers and affiliate infrastructure used to deliver fake-update/browser-in-the-browser installers and other payloads that have been used to stage ransomware and follow-on intrusions. While the action should reduce current malvertising campaigns, Evil Corp-linked actors remain a high-impact, resilient threat and may reconstitute infrastructure or shift delivery methods.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
8e03f0d5d464a0520d7e1c5c46a252dba2ebad3f85ae42d04a0e70b562a3bc90
Enrichment time
2026-06-21T20:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.