logo

Bengal Cat Lovers in Australia Targeted by Gootloader Malware

ID: 20f43f12-e2c8-5d0d-a2b9-9b9f44efc8f0

STIX ID: report--20f43f12-e2c8-5d0d-a2b9-9b9f44efc8f0

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2024-11-07

Date Updated: 2026-04-22

Author: do son

...
...

Sophos X-Ops observed a targeted GootLoader SEO-poisoning campaign that lured Australian Bengal cat owners to malicious search results; victims downloaded ZIP files containing JavaScript loaders that drop obfuscated payloads, create a persistent "Business Aviation" scheduled task (run via wscript.exe), and call back to attacker-controlled domains. The platform acts as an initial-access-as-a-service capable of delivering post-exploitation tools and ransomware, and evidence includes PowerShell commands sending Base64-encoded environment data and identified callhome domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.