logo

GootLoader uses malformed ZIP files to bypass security controls

ID: 24a264a4-8328-546b-a855-de81f68d07eb

STIX ID: report--24a264a4-8328-546b-a855-de81f68d07eb

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-01-18

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

This report describes GootLoader’s use of intentionally malformed ZIP files—hundreds of concatenated ZIPs with randomized metadata—to evade analysis and deliver JavaScript loaders that lead to payloads (including ransomware families like REvil and SunCrypt). It explains the infection chain (browser-decoded data → Windows unarchiver → JScript via wscript/cscript → PowerShell and persistence), provides detection recommendations (monitor wscript/cscript execution from Temp, LNK creation in Startup, and suspicious process chains), and links the activity to tracked actors (UNC2565/Vanilla Tempest).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.