Gootloader Malware Spreads via Google Ads with Weaponized Documents
ID: 51731b49-254c-5848-9566-82839d1ea2bd
STIX ID: report--51731b49-254c-5848-9566-82839d1ea2bd
Feed Name: GBHackers
**Executive Summary:** The Gootloader malware has resurfaced in a campaign that uses Google Ads and fake legal-document websites (for example lawliner.com and email from skhm.org) to trick users into downloading ZIPs containing malicious .js files; the payloads create persistence via scheduled tasks, run PowerShell to fetch additional components from compromised or decoy WordPress sites, communicate with C2 servers, and can deliver modular payloads including ransomware and banking trojans. Recommended actions include blocking campaign domains at web and email gateways, searching historical logs for interactions with those domains, improving endpoint detection for obfuscated scripts, and user education about downloading files from unverified sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
