Europol-led operation disrupts three malware networks
In an international operation coordinated by Europol and Eurojust, law enforcement agencies worked with private technology partners to disrupt three active malware networks: SocGholish, Amadey and StealC. SocGholish distributes fake browser updates through compromised websites, typically built on WordPress, and serves as an initial access point for further attacks. Amadey spreads through phishing and loads payloads including StealC, an infostealer that collects credentials, browser cookies and cryptocurrency wallet data and is sold as a service with its own web panel. According to Microsoft, Amadey and StealC were linked to more than 140,000 infected computers in the first two weeks of May alone. Over 200 domains and IP addresses were taken down through court orders, seizures and other means, and infected WordPress sites were cleaned up with their owners notified.
What this means for your organisation
The operation removes infrastructure, not infections. Credentials already stolen remain in circulation and continue to be used for account takeover. If your organisation runs a WordPress site, it may have been part of the distribution chain without anyone noticing, and it is the site owner who answers for that to visitors and regulators.
Berigo recommends
- Review your WordPress installations for unexpected changes, and update core, themes and plugins.
- Enable two-factor authentication for everyone who administers the site.
- Treat any credentials that may have been exposed as compromised and rotate them.
- Look for signs of infostealers on client machines, not only on servers.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch