Gootloader with Low Detection Rate Bypasses Most Security Tools
ID: e3af5cec-9560-5b9d-afd7-5593d3a19605
STIX ID: report--e3af5cec-9560-5b9d-afd7-5593d3a19605
Feed Name: cybersecurityNews.com
Gootloader resurfaced in November 2025 as a sophisticated initial-access malware used by the threat actor group Vanilla Tempest to facilitate Rhysida ransomware; it delivers JScript inside deliberately malformed and concatenated ZIP archives that reliably execute on Windows while evading common analysis and detection, uses persistence via Startup link files and obfuscated PowerShell to fetch payloads, and employs "hashbusting" to thwart signature-based defenses — recommended mitigations include blocking JScript execution, monitoring PowerShell process chains and NTFS shortname usage, and scanning for malformed ZIP structures with YARA rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
