logo

Gootloader with Low Detection Rate Bypasses Most Security Tools

ID: e3af5cec-9560-5b9d-afd7-5593d3a19605

STIX ID: report--e3af5cec-9560-5b9d-afd7-5593d3a19605

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-20

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Gootloader resurfaced in November 2025 as a sophisticated initial-access malware used by the threat actor group Vanilla Tempest to facilitate Rhysida ransomware; it delivers JScript inside deliberately malformed and concatenated ZIP archives that reliably execute on Windows while evading common analysis and detection, uses persistence via Startup link files and obfuscated PowerShell to fetch payloads, and employs "hashbusting" to thwart signature-based defenses — recommended mitigations include blocking JScript execution, monitoring PowerShell process chains and NTFS shortname usage, and scanning for malformed ZIP structures with YARA rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.