1
Groups Using This
1
Platforms
125
Prevalence Rank
0
Known Aliases
Description

SocGholish is a JavaScript-based loader malware that has been used since at least 2017. It has been observed in use against multiple sectors globally for initial access, primarily through drive-by-downloads masquerading as software updates. SocGholish is operated by Mustard Tempest and its access has been sold to groups including Indrik Spider for downloading secondary RAT and ransomware payloads.

View MITRE record ↗

Platforms
Windows
Groups Deploying SocGholish (1)
↑