Keitaro, ParrotTDS, TA2726, and SocGholish
Follow a current, documented fake-update ecosystem from compromised websites to GhoLoader.
In this lesson, you will learn to:
- Reconstruct the named TA569 delivery chain.
- Distinguish Keitaro abuse from ParrotTDS and actor ownership.
Keitaro, ParrotTDS, TA2726, and SocGholish
Uses Proofpoint’s 2023 landscape and June 2026 Operation Endgame reporting to separate a legitimate Keitaro product, TA2726-operated service, TA569, ParrotTDS, SocGholish, and payload outcomes.
Keitaro is dual-use; the instance and operation matter
Keitaro Tracker is a commercial advertising and campaign-tracking product. Proofpoint has repeatedly observed threat actors using actor-controlled Keitaro instances to filter malicious traffic. In the fake-browser-update landscape, compromised websites carried injected code that sent selected visitors through Keitaro before an actor-controlled second-stage domain displayed a lure and offered JavaScript or other payloads.
This distinction is analytically important. A Keitaro artifact can identify software behavior or an instance, but it does not make every Keitaro customer malicious. Collect the endpoint, configuration pattern, campaign token, redirect behavior, surrounding domains, and destination. Tie the assessment to the observed chain and dates. Product detection should create an investigation candidate, not a universal block decision.
TA569 can reach SocGholish through two TDS paths
Proofpoint tracks the SocGholish or FakeUpdates distributor as TA569. Its compromised-site injections impersonate browser updates and deliver GhoLoader. Reporting has documented a TA2726-operated malicious Keitaro service used by TA569 and an actor-owned ParrotTDS path, also called NDSW/NDSX. Parrot injections can be distributed across several JavaScript files on one compromised site.
Proofpoint’s June 2026 Operation Endgame report gave example paths: compromised website → TA2726 → TA569 → SocGholish injection → GhoLoader for selected Windows visitors in the United States, Canada, and Australia; and ParrotTDS → TA569 → GhoLoader for selected visitors in the United States, Canada, Great Britain, and the Netherlands. The same TA2726 Keitaro service also routed traffic for TA2727, demonstrating service sharing.
Operation Endgame changed the 2026 landscape
In June 2026, Proofpoint and Infoblox reported coordinated disruption of SocGholish infrastructure and remediation of compromised websites. Infoblox reported 106 servers and domains taken down and 14,971 compromised WordPress websites remediated. Treat these numbers as reporting from that operation, not a permanent count of every TA569 asset.
Disruption does not erase the learning value. Defenders can detect unexpected scripts in websites, outgoing connections from trusted sites to rotating TDS domains, fake-update pages, browser downloads followed by script execution, and GhoLoader activity. Website owners should reset compromised credentials, remove injection and persistence, patch the initial weakness, inspect logs, and watch for reinfection—not merely delete the visible script.
Resources
- Proofpoint: Fake Browser Update Landscape — Compare SocGholish, Keitaro, ParrotTDS, RogueRaticate, ClearFake, and other distinct fake-update clusters.
- Proofpoint: Operation Endgame and SocGholish — Use the June 2026 report for current TA569, TA2726, ParrotTDS, GhoLoader, and disruption details.
- Infoblox: Operation Endgame and SocGholish — Use the June 2026 source for the reported server, domain, and remediated WordPress-site counts.