Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Abuse & Phishing Europol

Police dismantle SocGholish botnet infecting 15,000 WordPress sites

A multinational operation removed malware from nearly 15,000 compromised WordPress sites linked to the Russian cybercrime group Evil Corp.

Police dismantle SocGholish botnet infecting 15,000 WordPress sites
Athena Sandrini · Pexels

A multinational law enforcement effort has disrupted one of the largest malware distribution networks targeting WordPress sites. The operation, conducted under the umbrella of Operation Endgame, removed SocGholish malware from nearly 15,000 compromised websites and took offline more than 100 servers linked to the Russian cybercrime group Evil Corp. Authorities from the Netherlands, Canada, the United States, and Germany collaborated in the takedown, which marks a significant blow to a malware family active since at least 2017.

What happened

On 18 June 2026, law enforcement agencies announced the results of a coordinated action against the SocGholish botnet, a JavaScript-based malware downloader also known as FakeUpdates and GhoLoader. The Dutch National High Tech Crime Unit (NHCTU) led the technical effort to clean 14,971 infected WordPress sites, while authorities in the U.S., Canada, and Germany took down 106 servers and domains used to control the botnet. The operation was supported by Europol and Eurojust, reflecting the cross-border nature of the threat.

SocGholish operates by hijacking legitimate WordPress sites and injecting malicious code that tricks visitors into downloading fake browser updates. Once installed, the malware establishes a connection to attackers, allowing them to deploy additional payloads, including ransomware and banking trojans. The malware has been linked to multiple high-profile cybercrime campaigns, including the distribution of Dridex, Doppelpaymer, and WastedLocker ransomware.

Background

Background: SocGholish is a JavaScript-based malware downloader that has been active since at least 2017. It primarily targets WordPress sites, which are widely used for business and personal websites. The malware is often distributed through compromised plugins or themes, and it tricks users into downloading malicious updates by mimicking legitimate software prompts. Evil Corp, the Russian cybercrime group behind SocGholish, has been active since 2007 and is known for its involvement in high-profile ransomware attacks.

Why it matters

The takedown of SocGholish represents a significant disruption to Evil Corp’s operations, which have long relied on the malware to distribute ransomware and other malicious payloads. By removing the malware from nearly 15,000 sites, law enforcement has not only reduced the immediate threat to visitors but also weakened the group’s ability to launch future attacks. The operation also highlights the growing collaboration between international agencies to combat cybercrime, particularly when it involves infrastructure hosted across multiple jurisdictions.

For website owners, the operation serves as a reminder of the importance of securing WordPress installations. The Dutch police advised affected site owners to change credentials, enable multi-factor authentication, remove unknown user accounts, and ensure their sites are updated to the latest version. Failure to do so could leave sites vulnerable to reinfection or exploitation by other threat actors.

What to watch

While the operation has dealt a blow to SocGholish, law enforcement has indicated that this is only the beginning of further actions against the malware and its operators. Maikel Rollman of the NHCTU stated that the takedown "marks the beginning of further action against SocGholish," suggesting that additional measures may be taken to dismantle the remaining infrastructure. Security researchers will likely monitor the botnet’s activity closely to assess whether the group attempts to rebuild or shift to alternative distribution methods.

Operation Endgame, the broader initiative under which this action was conducted, has previously targeted other major malware operations, including Rhadamanthys, VenomRAT, and Elysium. The operation’s focus on disrupting infection chains and botnet infrastructure underscores a strategic shift in law enforcement’s approach to combating cybercrime, prioritizing the dismantling of distribution networks over individual arrests.

For professionals

For professionals: Website administrators, particularly those managing WordPress sites, should audit their installations for signs of compromise, such as unknown user accounts or unauthorized code changes. Enabling multi-factor authentication and keeping plugins and themes updated are critical steps to prevent infection. Security teams should also monitor for indicators of compromise (IoCs) associated with SocGholish, as the malware may resurface through new domains or servers.

Companies mentioned

Europol WordPress

Discussion · coming soon

Be the first to join the thread when community discussion launches.