Episode

PP104: How SocGholish Picks Locks to Let In Ransomware

Podcast
Packet Protector
Published
Apr 7, 2026
Duration seconds
1699
Processing state
not_requested
Canonical source
https://packetpushers.net/podcasts/packet-protector/pp104-how-socgholish-picks-locks-to-let-in-ransomware/
Audio
https://feeds.packetpushers.net/link/23910/17315346/PP104.mp3
JSON
/v1/public/podcasts/packet-protector-6781347/episodes/pp104-how-socgholish-picks-locks-to-let-in-ransomware
Markdown
/podcast/packet-protector-6781347/pp104-how-socgholish-picks-locks-to-let-in-ransomware.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/packet-protector-6781347/episodes/pp104-how-socgholish-picks-locks-to-let-in-ransomware/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/packet-protector-6781347/pp104-how-socgholish-picks-locks-to-let-in-ransomware.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

In the cybercrime industry, initial access brokers specialize in break-ins. They pick digital locks and slide open electronic windows, and then sell that access to other threat actors who specialize in ransomware, exfiltration, and other crimes. SocGholish is a widely used tool in the access broker toolkit. Typically disguised as a legitimate software update, SocGholish ... Read more »