PP104: How SocGholish Picks Locks to Let In Ransomware

The Everything Feed - All Packet Pushers Pods28mApril 7, 2026

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “PP104: How SocGholish Picks Locks to Let In Ransomware” inside PodZeus.

AI-Generated Summary

In this live episode recorded at RSA 2026, Drew Connery-Murray and Jennifer welcome Anna Pham, Senior Technical and Response Analyst at Huntress Labs, to discuss the long-standing and highly effective malware framework known as SockGholish (or SotGolish). Anna breaks down how this JavaScript-based attack has been infecting millions of WordPress websites since 2017, using fake update pages to trick users into downloading malicious scripts. Once executed, the malware performs stealthy credential theft, browser hijacking, and man-in-the-middle attacks via fake root certificates, all while remaining undetected due to low resource usage. The threat actor behind SockGholish operates as an initial access broker, selling access and stolen data to ransomware groups and other cybercriminals. Despite its age, the framework remains unchanged and highly effective, relying on social engineering and outdated user behaviors like double-clicking scripts. Anna emphasizes that simple, actionable defenses—like deploying group policies to open scripts in Notepad++ instead of executing them—can drastically reduce risk. She also discusses related threats like ClickFix and the growing use of AI in malware development, noting telltale signs such as overly verbose comments and emojis in code. The episode concludes with a candid look at the psychology behind these attacks and the importance of proactive detection and defense.

Key Takeaways
1

Deploy group policies to prevent double-click execution of JavaScript files—open them in Notepad++ instead.

2

SockGholish uses fake update pages on compromised WordPress sites to deliver malware via social engineering.

3

The malware performs stealthy browser credential theft, crypto wallet hijacking, and man-in-the-middle attacks using fake root certificates.

4

Despite being active since 2017, SockGholish remains effective due to its unchanged, low-tech approach and widespread target exposure.

5

Threat actors use SockGholish as an initial access broker, selling access and data to ransomware and other cybercriminal groups.

…and 3 more takeaways available in PodZeus

Chapters
0:00
2 min

Welcome to RSA 2026 & Introducing Anna Pham

The hosts welcome listeners to the live episode from RSA 2026 in San Francisco and introduce Anna Pham, Senior Technical and Response Analyst at Huntress Labs, who has just delivered a talk on SockGholish.

2:00
3 min

What Is SockGholish? The Fake Update Scam

It's just a JavaScript-based framework... whenever the user visits the compromised website, they will serve a fake update page, prompting the user to download the updated script or whatever, to update the page.

Highlight
5:00
5 min

Why SockGholish Still Works After 9 Years

They never change it. It's very effective. If it works. Yeah, if it was worse. Why would they change it, right?

Highlight
10:00
5 min

How SockGholish Steals Credentials & Hijacks Traffic

They're doing a lot of things, right? Reconnaissance, data infiltration.

Highlight
15:00
5 min

Detection, Indicators, and Simple Defenses

It's just an elegantly simple thing to do. Let's try this one weird trick.

Highlight
High-Impact Quotes
They never change it. It's very effective. If it works. Yeah, if it was worse. Why would they change it, right?
Anna Pham8:53
Viral: 85.0
AI would tell you how it works. So you're actually able to see in their Python script the comments as well?
Anna Pham21:54
Viral: 80.0
It's just an elegantly simple thing to do. Let's try this one weird trick.
Drew Connery-Murray14:22
Viral: 78.0
Speakers

Hosts

Drew Connery-MurrayJennifer

Guest

Anna Pham
Topics Discussed
SockGholish Malware Framework95%Initial Access Brokers88%Browser Credential Theft85%Social Engineering Attacks82%Group Policy Security Controls80%AI in Malware Development78%WordPress Security75%DNS-Based Command and Control70%
People & Brands

Anna Pham

person

45xPositive

SockGholish

other

38xNegative

Huntress Labs

organization

22xPositive

WordPress

other

18xNeutral

ClickFix

other

15xNegative

JavaScript

other

14xNeutral

PowerShell

product

12xNeutral

AI

other

12xNeutral

RSA 2026

other

10xPositive

DNS

other

8xNeutral

Get the full intelligence

Search transcripts, export clips, track mentions, and explore all topics from “PP104: How SocGholish Picks Locks to Let In Ransomware” inside PodZeus.

Start discovering podcast insights today

Start with a 7-day trial and explore a growing catalog of popular podcasts. No credit card required.

No credit card required • 7-day trial • Cancel anytime