#FakeUpdates
Check Pointin mukaan FakeUpdates on merkittävä kyberuhka ja keskeinen väline kiristyshaittaohjelmahyökkäyksissä. FakeUpdates levittää muita haittaohjelmia.

dawn.fi/uutiset/2025...
Suomessakin yleinen haittaohjelma FakeUpdates on keskeinen väline kiristyshaittaohjelmahyökkäyksissä
FakeUpdates on merkittävä kyberuhka ja keskeinen väline kiristyshaittaohjelmahyökkäyksissä. FakeUpdates levittää muita haittaohjelmia.
dawn.fi
February 17, 2025 at 7:02 PM
Aus dem Feed: ⟪ Cyberkriminelle kapern tausende vertrauenswürdige Webseiten für DriveSurge-Angriffe ⟫ https://www.it-daily.net/shortnews/drivesurge-angriffe-webseiten | #medien #design
➔ „Die Kampagne DriveSurge nutzt zTDS, FakeUpdates und Clipboard-Hijacking, um Besucher gekaperter …
DriveSurge-Angriffe: Cyberkriminelle kapern Webseiten
Die Kampagne DriveSurge nutzt zTDS, FakeUpdates und Clipboard-Hijacking, um Besucher gekaperter Webseiten unbemerkt mit Schadsoftware zu infizieren.
www.it-daily.net
June 8, 2026 at 10:58 AM
#SocGholish, the “FakeUpdates” web injects framework linked to major ransomware events, has been disrupted by #OperationEndgame.

❌ 100 servers and domains worldwide dismantled
❌ 14,971 websites remediated

Learn more: www.proofpoint.com/us/blog/thre.... 🧵⤵️
June 18, 2026 at 3:09 PM
Compromised website > #SocGholish > #FakeUpdates:

Date Observed: 2026-01-09

IOCs:
hxxps://personal[.]courtpsychologists[.]com/3tCck6Xy//q68qah6OKwsa2k+eP86r7/v774+rC3w/W3vPmx8vLuseTy7eqoo/r8rKf9+rKh6fS6qPf+tbe+7g==
hxxps://files[.]kaliesthenics[.]com/XgdK7BK310zDHSb5ucu3tSdD7BKqkw==
January 27, 2026 at 5:05 AM
Watch out as new research shows SocGholish Malware as Service (MaaS) is exploiting compromised websites and fake software updates to push ransomware and infostealers worldwide.

Read: hackread.com/socgholish-m...

#SocGholish #Malware #FakeUpdates #Ransomware #InfoStealer
SocGholish Malware Using Compromised Sites to Deliver Ransomware
New research on SocGholish (FakeUpdates) reveals how this MaaS platform is used by threat actors like Evil Corp and RansomHub to compromise websites, steal data, and launch high-impact attacks on heal...
hackread.com
October 22, 2025 at 2:06 PM
A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites.
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites.
www.bleepingcomputer.com
June 1, 2026 at 10:14 PM
Law enforcement action Operation Endgame took down 106 servers and domains and cleaned 14,971 infected WordPress sites that had been silently redirecting visitors into the FakeUpdates malware trap.
Nearly 15,000 infected websites cleaned in SocGholish crackdown
Thousands of everyday websites were cleaned as part of a global operation targeting the malware network behind fake browser update scams.
bit.ly
June 19, 2026 at 6:38 PM
NEW: Check Point’s April 2025 malware report reveals increasingly sophisticated attacks using familiar malware like FakeUpdates, Remcos, and AgentTesla. #Education remains the top targeted sector.

Read: hackread.com/fakeupdates-...

#CyberSecurity #Malware #InfoStealers #InfoSec
FakeUpdates, Remcos, AgentTesla Top Malware Charts in Stealth Attack Surge
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
hackread.com
May 12, 2025 at 4:46 PM
2024-12-17 (Tues): #SmartApeSG injected script leads to fake browser update page that leads to #NetSupport #RAT infection. A #pcap of the infection traffic, associated malware samples and more information is available at www.malware-traffic-analysis.net/2024/12/17/i...

#FakeUpdates #NetSupportRAT
December 17, 2024 at 4:57 AM
2025年3月のサイバー脅威: FakeUpdatesとRansomHubが猛威を振るう#チェック・ポイント#RansomHub#FakeUpdates

チェック・ポイント・リサーチが発表した2025年3月の脅威インデックスは、FakeUpdatesとRansomHubの影響力を示しており、教育分野が最も多くの被害を受けています。
2025年3月のサイバー脅威: FakeUpdatesとRansomHubが猛威を振るう
チェック・ポイント・リサーチが発表した2025年3月の脅威インデックスは、FakeUpdatesとRansomHubの影響力を示しており、教育分野が最も多くの被害を受けています。
news.3rd-in.co.jp
April 24, 2025 at 2:49 AM
Compromised website > #SocGholish > #FakeUpdates:

Date Observed: 2026-01-08

IOCs:
hxxps://personal[.]courtpsychologists[.]com/zWhOurZKLdOpSnSI+1pimL4cK8rvUmzWrAYq06MPEdykBCuY4Uo8mPdKJMDvFQ==
hxxps://docs[.]exitdriving[.]school/XgdK7BK310zDHSb5ucu3tSdD7BKqkw==
January 27, 2026 at 5:04 AM
FakeUpdates-latausohjelma pitää edelleen ykköspaikkaa maailman osalta, mutta Suomessa sen syrjäytti toiseksi Injuke-troijalainen.

dawn.fi/uutiset/2024...
Kalastelusähköpostien kautta leviävä haittaohjelma nousi Suomen yleisimmäksi
FakeUpdates-latausohjelma pitää edelleen ykköspaikkaa maailman osalta, mutta Suomessa sen syrjäytti toiseksi Injuke-troijalainen.
dawn.fi
March 13, 2024 at 12:43 PM
Compromised website > #SocGholish > #FakeUpdates:

Date Observed: 2026-01-07

IOCs:
hxxps://personal[.]courtpsychologists[.]com/RPesej/VzxMg1ZZIcsWAWDeDyQpmzY4WJZnIEyqQ8xwtm8lYaNXeWH7V3h431dE=
hxxps://export[.]galmabuna[.]com/XgdK7BK310zDHSb5ucu3tSdD7BKqkw==
January 27, 2026 at 5:03 AM
Compromised website > #SocGholish > #FakeUpdates:

Date Observed: 2026-01-06

IOCs:
hxxps://personal[.]courtpsychologists[.]com/RPesej/VzxMg1ZZIcsWAWDeDyQpmzY4WJZnIEyqQ8xwtm8lYaNXeWH7V3h431dE=
hxxps://order[.]lelispices[.]com/XgdK7BK310zDHSb5ucu3tSdD7BKqkw==
January 27, 2026 at 5:00 AM
DriveSurge is behind a large-scale campaign hijacking thousands of legit sites via zTDS to deliver ClickFix and FakeUpdates, with added infrastructure for ad distribution and macOS payload staging. #DriveSurge #ClickFix #FakeUpdates
Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
Silent Push identified DriveSurge, a specialized Initial Access Broker using zTDS to hijack thousands of legitimate websites and redirect victims to ClickFix and FakeUpdates delivery chains at scale. The investigation also uncovered related infrastructure for ad distribution and macOS payload staging, including domains, IPs, and server fingerprints tied to DriveSurge’s broader...
www.hendryadrian.com
May 30, 2026 at 2:45 PM
Compromised website > #SocGholish > #FakeUpdates:

Date Observed: 2025-11-21

IOCs:
hxxps://cp[.]envisionfonddulac[.]biz/O4ZClECkIf1fpHimDLJutkjvJrYBt3usD7FypBekMLYBpCf2Qf805k3sK/FP7SD2Texg6Q==
hxxps://feedback[.]rightontheroad[.]com/XgdK7BK3HCfM1NTjHQdfioToH0dbtc451v7D7cs3eBWT
November 23, 2025 at 11:26 PM
Compromised website > #SocGholish > #FakeUpdates:

Date Observed: 2026-01-24

IOCs:
hxxps://booking[.]skylinecarwashfm[.]com/Vw93kywtFPozLU2hYT1bsSR7EuN1NVX/NmET+jloKPU+YxKxey0FsW0tEf8ufBbnI2FV7g==
hxxps://special[.]blainrealtor[.]net/XgdK7BK310zDHSb5ucu3tSdD7BKqkw==
February 9, 2026 at 5:10 AM
Check Point Research nostaa marraskuun haittaohjelmakatsauksessaan esille uuden AsyncRAT-kampanjan ja Fakeupdates-haittaohjelman, joka on nyt Suomen yleisin.

dawn.fi/uutiset/2023...

#CheckPoint #haittaohjelmat #troijalainen #tietoturva #uutiset
Väärennettyjä selainpäivityksiä kauppaava haittaohjelma Suomen yleisin
Check Point Research nostaa marraskuun haittaohjelmakatsauksessaan esille uuden AsyncRAT-kampanjan ja Fakeupdates-haittaohjelman, joka on nyt Suomen yleisin.
dawn.fi
December 14, 2023 at 12:50 PM
DriveSurge e il sistema zTDS: migliaia di siti dirottati per distribuire ClickFix e FakeUpdates su Windows e macOS
il blog: insicurezzadigitale.com/drivesurge-e...

#cybersecurity #cybercrime #cyberpedia #infosec #malware #phishing #trojan
June 4, 2026 at 7:50 AM
CTA member @silentpush.bsky.social on DriveSurge:
"What makes DriveSurge notable isn’t just the volume of its activity; it’s the sophistication of its infrastructure, the breadth of its targets, and the fact that it has been operating largely undetected until now"
www.silentpush.com/blog/drivesu...
Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attacks in Thousands of Compromised Sites
Silent Push observed several drive-by attack clusters using ClickFix and FakeUpdates campaigns. We named the primary driver DriveSurge.
www.silentpush.com
May 31, 2026 at 1:37 PM
TRAC Labs analyses SocGholish/FakeUpdates. The infection chain starts with a fake browser update delivered via compromised websites & a malicious JavaScript file, leading to an obfuscated MintsLoader payload that delivers the GhostWeaver PowerShell backdoor. trac-labs.com/dont-ghost-t...
February 17, 2025 at 10:23 AM