logo

Gootloader Malware Spreads via Google Ads with Weaponized Documents

ID: 51731b49-254c-5848-9566-82839d1ea2bd

STIX ID: report--51731b49-254c-5848-9566-82839d1ea2bd

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

**Executive Summary:** The Gootloader malware has resurfaced in a campaign that uses Google Ads and fake legal-document websites (for example lawliner.com and email from skhm.org) to trick users into downloading ZIPs containing malicious .js files; the payloads create persistence via scheduled tasks, run PowerShell to fetch additional components from compromised or decoy WordPress sites, communicate with C2 servers, and can deliver modular payloads including ransomware and banking trojans. Recommended actions include blocking campaign domains at web and email gateways, searching historical logs for interactions with those domains, improving endpoint detection for obfuscated scripts, and user education about downloading files from unverified sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.