Global effort targeted fake computer updates tied to Russian cybercriminals: RCMP
Advertisement
Read this article for free:
or
Already have an account? Log in here »
To continue reading, please subscribe:
Digital Subscription
One year of digital access for only $205*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.
To continue reading, please subscribe:
Add Free Press access to your Brandon Sun subscription for only an additional
$1 for the first 4 weeks*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.
Read unlimited articles for free today:
or
Already have an account? Log in here »
OTTAWA – The RCMP says it worked with international partners to deal a blow to cybercriminals who trick users into downloading malicious files disguised as legitimate computer updates.
Investigators say SocGholish malware — linked to the Russian cybercriminal group Evil Corp — exploited thousands of WordPress sites with the aim of gaining unauthorized access to computer systems and data.
An RCMP media statement says the force teamed up with counterparts in the Netherlands, the United States and Germany on the joint action, part of an effort known as Operation Endgame.
A notice from the Dutch police says agencies took down 106 servers and domains worldwide, remediated almost 15,000 websites, cleaned infected WordPress sites and notified victims.
Authorities urged owners of WordPress sites to change their login credentials and enable multi‑factor authentication.
They advised people to prevent SocGholish malware infection by never trusting pop-ups that appear in browsers or overly flashy update notices that urge immediate action.
This report by The Canadian Press was first published June 19, 2026.
— with files from Aaron Sousa in Edmonton