js-GhoLoader

References:
  • Fake Software Update Abuses NetSupport Remote Access Too - 2018-04-05 - FireEye - Sudhanshu Dubey js-GhoLoader SocGholish
  • Deep Analysis of Queryn Campaign - 2018-07-10 - Github - Koike js-GhoLoader SocGholish
  • More Reading:

  • 2018-03-27 - FAKE CHROME, FIREFOX, OR FLASH UPDATE PAGES PUSH JS MALWARE - 2018-03-27 - Malware-Traffic-Analysis - Brad Duncan SocGholish js-GhoLoader
  • "FakeUpdates" campaign leverages multiple website platforms - 2018-04-10 - Malwarebytes - Jérôme Segura SocGholish js-GhoLoader Chthonic
  • Fake Updates campaign still active in 2019 - 2019-02-12 - SANS ISC - Brad Duncan SocGholish Chthonic js-GhoLoader