Police raid malware network tied to Russia's Evil Corp hacker group

2026-06-22T08:51:57Zc2a139f39f4734ecca4040b25761b1b4b83849c781c02cf6c48537e9fb0264f9
botnet-disruptionbrowser-malwarecritical-infrastructureevil-corpgentlemen-ransomwarelaw-enforcement-takedownloadermalwarenation-state-activityransomwaresocgholishsurveillance-exports

What happened

International law-enforcement action disrupted the SocGholish browser-based botnet linked to the Russia-associated cybercrime group Evil Corp, targeting command-and-control and distribution infrastructure and likely impacting the group’s ability to deliver loaders and ransomware. Related reporting in the batch includes a claimed ransomware attack on Australian sugar producer (claimed by the ‘Gentlemen’ group), concerns over Bulgarian export approvals for surveillance technology to repressive regimes, and UK warnings about nation-state prepositioning against critical infrastructure.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
c2a139f39f4734ecca4040b25761b1b4b83849c781c02cf6c48537e9fb0264f9
Enrichment time
2026-06-22T08:51:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.