Also known as: FakeUpdates
Executive Summary
SocGholish is a JavaScript loader that enables attackers to obtain initial access via drive‑by downloads masquerading as software updates. Once executed it fetches secondary RAT or ransomware components from a shared infrastructure owned by Mustard Tempest and sold to other malicious actors. This multi‑stage approach complicates detection and allows distributed teams to deliver payloads at scale.
Enhanced Description
SocGholish is a JavaScript‑based malicious loader that first appeared in publicly available reports around 2017 and has been consistently used against a diverse array of sectors worldwide. The malware’s primary vector is a sophisticated drive‑by download campaign, wherein unsuspecting users are tricked into installing what appears to be legitimate software updates. Once the initial script executes within the victim’s browser or web client, it immediately initiates an outbound connection to a command and control (C2) host controlled by an APT group known as Mustard Tempest. The core function of SocGholish is to act as a delivery engine for more destructive payloads. After establishing session persistence, the loader requests secondary malicious binaries – frequently remote administration tools or ransomware modules – from the same infrastructure. These subsequent payloads are typically downloaded via standard web protocols, obfuscating the traffic to evade straightforward signature‑based detection. In addition to its role as a stealthy initial access tool, SocGholish leverages social engineering tactics by masquerading updates with legitimate digital signatures or familiar branding. Its multi‑stage approach makes it particularly attractive to state‑level actors; analysts have documented that parts of its delivery chain were sold to other threat groups such as Indrik Spider for broader deployment. The combination of JavaScript execution, deceptive update mechanisms, and a reliable secondary payload pipeline places SocGholish among the more dangerous initial‑access loaders in today’s threat landscape.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available data provides a clear picture of SocGholish’s role as an initial access loader and its affiliation with Mustard Tempest, supported by multiple reputable vendors (SentinelOne, Red Canary, Secureworks). However, gaps remain regarding the exact distribution mechanisms, update frequency of its infrastructure, and potential variations across different campaign phases. Confidence in core capabilities is high, but detailed attribution of each operation remains partially inferred.
SocGholish is a JavaScript-based loader malware that has been used since at least 2017. It has been observed in use against multiple sectors globally for initial access, primarily through drive-by-downloads masquerading as software updates. SocGholish is operated by Mustard Tempest and its access has been sold to groups including Indrik Spider for downloading secondary RAT and ransomware payloads.(Citation: SentinelOne SocGholish Infrastructure November 2022)(Citation: SocGholish-update)(Citation: Red Canary SocGholish March 2024)(Citation: Secureworks Gold Prelude Profile)