Europol announced this week that a coordinated international operation — involving UK law enforcement, Microsoft, and several major security vendors — has dismantled the infrastructure behind three of the world’s most widely used pieces of malware: SocGholish, Amadey, and StealC. Investigators seized or disabled 326 servers and 142 domains, recovered around 27 million stolen login credentials, and froze more than €41 million in criminal crypto assets. It’s one of the largest cybercrime takedowns of the year — and the detail that matters most to UK SMEs is where this malware was actually hiding.

SocGholish didn’t spread through obvious hacking. It spread by quietly compromising legitimate, ordinary small business websites — restaurants, auto repair shops, local trades — and using them as launchpads. Nearly 15,000 infected sites were “remediated” as part of this operation alone. The business owners running those sites had no idea their site was infected, let alone that it was being used to attack other people’s customers.

How this actually works

The trick is simple and effective. Once a website’s content management system (commonly WordPress) is compromised — usually through an outdated plugin, weak admin password, or unpatched core software — attackers inject malicious code that shows visitors a fake “your browser needs updating” prompt. Anyone who clicks it downloads malware instead of an update. The website owner sees nothing unusual; their site still looks and functions normally. Meanwhile their domain’s reputation, and potentially their customers’ devices, are being quietly used as a distribution point for credential-stealing malware like StealC and loader malware like Amadey.

This is exactly the kind of compromise that’s invisible until someone tells you — a customer complains, your hosting provider suspends you, or your site gets flagged and blacklisted by browsers and search engines.

What to check this week

If you run a WordPress site, or any CMS, and haven’t checked it recently, this is a good week to do three things. First, update everything — core software, themes, and every plugin — since outdated plugins are still the single most common entry point for this kind of compromise. Second, review who has admin access and force a password reset on any account that isn’t using unique, strong credentials or multi-factor authentication. Third, look for anything odd: unexpected pop-ups, browser-update prompts, redirects, or new admin users you don’t recognise.

If any of that sounds beyond what you or your web person can confidently check, it’s worth getting a proper technical review rather than guessing. CoolCoding can audit a site’s technical health and close off the kind of plugin and access gaps that attacks like this one exploit. And if you want ongoing visibility rather than a one-off check — knowing quickly if your domain, credentials, or systems turn up in a breach or dark web dump — that’s precisely what KeepSafe monitors for, so you’re not finding out from a customer or a takedown notice.

The takeaway

Operation Endgame is good news — a genuinely large chunk of criminal infrastructure is gone. But the way it worked is a useful reminder for every UK small business with a website: you don’t need to be a target to become a weapon. An unpatched plugin sitting quietly on your site can turn it into infrastructure for attacking someone else entirely, without you ever noticing. A ten-minute plugin and access check this week costs nothing and closes the exact door this operation just found thousands of businesses had left open.

It’s also worth remembering that takedowns like this one rarely stay effective for long. Criminal groups tend to rebuild infrastructure elsewhere within months, often reusing the same techniques on the same soft targets — small business websites with outdated software and no one actively watching them. The businesses that stay off that list going forward are the ones that treat basic website hygiene as an ongoing habit rather than a one-off fix after the fact.