Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SocGholish, also known as FakeUpdates, is a JavaScript-based malware loader—not a genuine browser update. It is commonly delivered through compromised websites that show visitors a convincing update prompt. Security companies reported substantial SocGholish activity in different datasets, but their measurements use different populations and units; they do not establish one comparable global trend showing an uninterrupted surge.

What is SocGholish, or FakeUpdates?

SocGholish is a malware delivery operation built around JavaScript. MITRE ATT&CK says it has been used since at least 2017 and observed globally across sectors. The name FakeUpdates reflects its common lure: a webpage prompts a visitor to install what appears to be an update for the visitor’s browser or other familiar software.

The prompt is not itself proof that a device is infected. In the commonly documented chain, a visitor must download and run the offered file for the loader to execute. Visiting a compromised site without taking that step does not, on its own, establish that the device was infected.

How does a SocGholish drive-by attack work?

  1. A legitimate website is compromised. An attacker injects or appends malicious code to a website that visitors may otherwise trust.
  2. The code filters visitors and presents a lure. JavaScript may profile or filter traffic before showing a prompt. Proofpoint describes a typical TA569 chain as involving site injects, a traffic distribution service that selects which users receive a payload, and a later GhoLoader payload. The lure may imitate an update suited to the visitor’s browser.
  3. The visitor downloads and executes a file. The download format varies. Red Canary reported that among SocGholish detections in its 2025 dataset, about one third involved ZIP files and about two thirds used a direct JavaScript lure. Those proportions describe Red Canary’s detections, not all victims.
  4. The loader brings in additional tools or malware. MITRE associates SocGholish with drive-by compromise (T1189), JavaScript execution, software discovery, and ingress tool transfer. MS-ISAC has documented follow-on activity involving tools such as Cobalt Strike, PowerShell, NetSupport, and AsyncRAT, as well as information theft and ransomware in some cases.

Those follow-on outcomes are possibilities, not a guaranteed result of every infection. Compromised sites can also be abused by more than one actor, so a finding on one site does not necessarily describe every SocGholish campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Norton 360 Deluxe 2027 Antivirus, 3 Devices, Auto-Renews [Download]
  • ONGOING PROTECTION Download instantly & install protection for 3 PCs, Macs, iOS or Android devices in minutes!
  • TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
  • ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
  • REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
  • DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.

Do reports prove a worldwide surge?

No single global time series can be inferred from the published figures below. They come from different organizations, observation periods, detection methods, and units—ranging from infections found in a scanning dataset to customers affected or external-script references. Treat each as a measure of that organization’s own observations, not as a count of all infected sites.

Source and period Reported measure What it represents
Sucuri, 2024 147,332 SocGholish infections Infections identified in Sucuri’s SiteCheck dataset; not a census of every infected site worldwide.
GoDaddy, 2025 41,460 websites with SocGholish detected by signature-based scanning Websites found by GoDaddy’s scanning; a different detection unit from script references.
GoDaddy, 2025 60,753 instances of websites loading external scripts from 106 known SocGholish-associated domains External-script detections. These instances should not be added to the website figure as though they were additional distinct infected websites.
Red Canary, 2025 Threat Detection Report 2.3% of customers affected; rank #8 overall Red Canary’s customer population and report ranking, not a global prevalence estimate.
Check Point, January–December 2024 FakeUpdates (SocGholish) led its most prevalent malware rankings ThreatCloud comparisons of malware distribution in Check Point’s data; the ranking indicates wide distribution in that dataset, not that the malware was necessarily the most sophisticated or dangerous.

These reports support the conclusion that SocGholish remained a significant concern in their respective datasets. They do not establish a single comparable worldwide infection count or prove that activity rose continuously from one year to the next.

Rank #2
Sale
McAfee Total Protection 2027 Antivirus Software for 3 Devices | Auto-Renews
  • THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
  • PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
  • SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
  • GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
  • MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.

What should you do if a webpage shows a fake update?

  • Do not install an update offered by an unexpected webpage prompt, and do not run an unfamiliar downloaded script or archive.
  • Close the page and update the browser or software through its built-in update feature or the software vendor’s own update pathway.
  • If you only saw the prompt and did not download or execute its file, do not treat the prompt alone as confirmation of infection. If you did run the file, handle the device as a suspected compromise.

How do you respond if SocGholish may have run on a device?

Microsoft Security Intelligence advises updating antimalware definitions and running a full scan. Its guidance warns that remnants or system changes may persist and that a severely compromised device may require complete restoration from a clean, uninfected copy.

  1. In a managed workplace: contact the organization’s security or IT team promptly. Preserve evidence and follow its incident-response process before wiping, restoring, or otherwise changing the device.
  2. For a personal device: update the installed antimalware definitions and run a full scan. Follow the security product’s remediation instructions; if the device remains compromised or cannot be trusted, restore it from a known-clean backup or seek qualified incident-response help.

What should a website owner check?

A fake update prompt may originate from code injected into a website, so cleaning the visitor’s computer does not clean the site that served the lure. Sucuri has described NDSW/NDSX-style injection and PHP proxy behavior; GoDaddy has reported changes in injected code and fake plugins. These indicators evolve, so an old filename or code string is not a complete detection rule.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Norton 360 Deluxe 2027 Antivirus, 5 Devices, Auto-Renews [Download]
  • ONGOING PROTECTION Download instantly & install protection for 5 PCs, Macs, iOS or Android devices in minutes!
  • TOP-PERFORMING VPN Faster speeds, more server locations, and greater connection control to protect your privacy across all your devices, including Smart TVs.
  • ADVANCED SCAM PROTECTION Help spot hidden scams online. With the built-in Genie AI assistant, you’ll never wonder if a message or email is suspicious again.
  • REAL-TIME PROTECTION Advanced security protects against existing and emerging malware threats, including ransomware and viruses, and it won’t slow down your device performance.
  • DARK WEB MONITORING Identity thieves can buy or sell your information on websites and forums. We search the dark web and notify you should your information be found.
  • Review the site for injected or appended JavaScript, unfamiliar external script references, modified JavaScript or PHP files, suspicious PHP proxy files, and plugins or administrator accounts that were not authorized.
  • Investigate how the site was initially compromised, including unauthorized administrator access, and secure that entry point as well as removing malicious content.
  • Use a qualified website-security or malware-cleanup service if you cannot confidently identify the intrusion and verify that it is resolved. Deleting one suspicious script alone does not establish that the site is clean.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Did the June 2026 disruption end SocGholish?

Europol’s June 24, 2026 newsroom listing announced a global cyber strike that disrupted SocGholish, Amadey, and StealC networks. The accessible listing does not provide operational results such as infrastructure seized, websites cleaned, or arrests, and it does not establish that SocGholish activity stopped afterward. The announcement is a significant disruption, not evidence that the threat has ended.

Best Value
Sale
McAfee Total Protection 2027 Antivirus Software for 5 Devices | Auto-Renews
  • THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
  • PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
  • SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
  • GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
  • MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
Rank #4
Bitdefender Total Security 2026 – Complete Antivirus and Internet Security Suite – 5 Devices | 1 Year Subscription | PC/Mac | Activation Code by Mail
  • SPEED-OPTIMIZED, CROSS-PLATFORM PROTECTION: World-class antivirus security and cyber protection for Windows (Windows 7 with Service Pack 1, Windows 8, Windows 8.1, Windows 10, and Windows 11), Mac OS (Yosemite 10.10 or later), iOS (11.2 or later), and Android (5.0 or later). Organize and keep your digital life safe from hackers
  • SAFE ONLINE BANKING: A unique, dedicated browser secures your online transactions; Our Total Security product also includes 200MB per day of our new and improved Bitdefender VPN
  • ADVANCED THREAT DEFENSE: Real-Time Data Protection, Multi-Layer Malware and Ransomware Protection, Social Network Protection, Game/Movie/Work Modes, Microphone Monitor, Webcam Protection, Anti-Tracker, Phishing, Fraud, and Spam Protection, File Shredder, Parental Controls, and more
  • ECO-FRIENDLY PACKAGING: Your product-specific code is printed on a card and shipped inside a protective cardboard sleeve. Simply open packaging and scratch off security ink on the card to reveal your activation code. No more bulky box or hard-to-recycle discs. PLEASE NOTE: Product packaging may vary from the images shown, however the product is the same.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.