Back to news

Botnet Tied to Israeli Firm, WordPress Cleanup Marks Dual Cyber Crackdowns

International police dismantle SocGholish infrastructure while researchers expose an Android botnet linked to a publicly traded Israeli proxy company.

Botnet Tied to Israeli Firm, WordPress Cleanup Marks Dual Cyber Crackdowns

What happened

A multinational law enforcement coalition spanning the Netherlands, Canada, Germany, and the United States has dismantled server infrastructure underpinning the SocGholish malware network and remediated nearly 15,000 compromised WordPress sites as part of the continuing Operation Endgame campaign. Separately, cybersecurity researchers from several firms have traced a four-year-old Android-based botnet, dubbed Popa, to NetNut, a residential proxy service operated by the publicly traded Israeli company Alon. The Popa botnet is believed to have conscripted millions of consumer television set-top boxes into a network used for advertising fraud, credential theft, and large-scale data scraping.

Why it matters for your business

WordPress remains one of the most widely deployed web platforms in the world, and the SocGholish campaign demonstrates how threat actors weaponize legitimate sites to distribute malware to unsuspecting visitors — putting both site owners and their customers at risk. Organizations running WordPress installations should treat plugin and core updates as a non-negotiable security control, not a maintenance afterthought. The Popa findings raise a harder question: residential proxy services marketed as legitimate network infrastructure can mask malicious traffic at scale, complicating threat detection and vendor due-diligence processes. Operations leaders evaluating third-party network or analytics vendors should scrutinize the provenance of proxy traffic in their supply chain.

What to watch next

Operation Endgame has already produced multiple waves of arrests and infrastructure seizures since its launch, suggesting further enforcement actions against affiliated threat actors remain probable. The Popa-NetNut connection will likely draw regulatory and investor scrutiny toward the parent company, potentially setting a precedent for how authorities treat commercially operated infrastructure implicated in botnet activity. Security teams should monitor whether either development triggers new indicators of compromise or updated threat intelligence feeds relevant to their own environments.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp