PP104: How SocGholish Picks Locks to Let In Ransomware
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “PP104: How SocGholish Picks Locks to Let In Ransomware” inside PodZeus.
In this live episode recorded at RSA 2026, Drew Connery-Murray and Jennifer welcome Anna Pham, Senior Technical and Response Analyst at Huntress Labs, to discuss the long-standing and highly effective malware framework known as SockGholish (or SotGolish). Anna breaks down how this JavaScript-based attack has been infecting millions of WordPress websites since 2017, using fake update pages to trick users into downloading malicious scripts. Once executed, the malware performs stealthy credential theft, browser hijacking, and man-in-the-middle attacks via fake root certificates, all while remaining undetected due to low resource usage. The threat actor behind SockGholish operates as an initial access broker, selling access and stolen data to ransomware groups and other cybercriminals. Despite its age, the framework remains unchanged and highly effective, relying on social engineering and outdated user behaviors like double-clicking scripts. Anna emphasizes that simple, actionable defenses—like deploying group policies to open scripts in Notepad++ instead of executing them—can drastically reduce risk. She also discusses related threats like ClickFix and the growing use of AI in malware development, noting telltale signs such as overly verbose comments and emojis in code. The episode concludes with a candid look at the psychology behind these attacks and the importance of proactive detection and defense.
Deploy group policies to prevent double-click execution of JavaScript files—open them in Notepad++ instead.
SockGholish uses fake update pages on compromised WordPress sites to deliver malware via social engineering.
The malware performs stealthy browser credential theft, crypto wallet hijacking, and man-in-the-middle attacks using fake root certificates.
Despite being active since 2017, SockGholish remains effective due to its unchanged, low-tech approach and widespread target exposure.
Threat actors use SockGholish as an initial access broker, selling access and data to ransomware and other cybercriminal groups.
…and 3 more takeaways available in PodZeus
Welcome to RSA 2026 & Introducing Anna Pham
The hosts welcome listeners to the live episode from RSA 2026 in San Francisco and introduce Anna Pham, Senior Technical and Response Analyst at Huntress Labs, who has just delivered a talk on SockGholish.
What Is SockGholish? The Fake Update Scam
“It's just a JavaScript-based framework... whenever the user visits the compromised website, they will serve a fake update page, prompting the user to download the updated script or whatever, to update the page.”
Why SockGholish Still Works After 9 Years
“They never change it. It's very effective. If it works. Yeah, if it was worse. Why would they change it, right?”
How SockGholish Steals Credentials & Hijacks Traffic
“They're doing a lot of things, right? Reconnaissance, data infiltration.”
Detection, Indicators, and Simple Defenses
“It's just an elegantly simple thing to do. Let's try this one weird trick.”
“They never change it. It's very effective. If it works. Yeah, if it was worse. Why would they change it, right?”
“AI would tell you how it works. So you're actually able to see in their Python script the comments as well?”
“It's just an elegantly simple thing to do. Let's try this one weird trick.”
Hosts
Guest
Anna Pham
person
SockGholish
other
Huntress Labs
organization
WordPress
other
ClickFix
other
JavaScript
other
PowerShell
product
AI
other
RSA 2026
other
DNS
other
PP103: FireMon Brings Clarity to Firewall Rule Chaos (Sponsored)
The Everything Feed - All Packet Pushers Pods • 56m • 3/31/2026
HW074: Build Your Own Access Point with Bradley Wegner
The Everything Feed - All Packet Pushers Pods • 26m • 3/31/2026
NAN118: The Importance of the Data Behind AI in Networks (Sponsored)
The Everything Feed - All Packet Pushers Pods • 43m • 4/1/2026
D2DO299: The State of Platform Engineering and DevEx
The Everything Feed - All Packet Pushers Pods • 43m • 4/1/2026
N4N052: Multicast Part 2
The Everything Feed - All Packet Pushers Pods • 1h 25m • 4/2/2026
Get the full intelligence
Search transcripts, export clips, track mentions, and explore all topics from “PP104: How SocGholish Picks Locks to Let In Ransomware” inside PodZeus.
Start discovering podcast insights today
Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.
No credit card required • 7-day trial • Cancel anytime
