logo

Gootloader Malware With Low Detection Rate Evades Most Security Tools

ID: 3fc00a80-3844-555f-ada7-520be06484ee

STIX ID: report--3fc00a80-3844-555f-ada7-520be06484ee

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-01-20

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Gootloader resurfaced in late 2025 using intentionally malformed ZIP archives (hundreds of concatenated archives and truncated End of Central Directory records) and hashbusting to bypass extraction and signature-based detection; the campaign delivers obfuscated JScript that uses WOFF2 Z85-encoded glyphs and NTFS 8.3 short-name LNK persistence to execute and escalate rapidly, facilitating lateral movement and ransomware deployment by affiliated criminal actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.