Bengal Cat Lovers in Australia Targeted by Gootloader Malware
ID: 20f43f12-e2c8-5d0d-a2b9-9b9f44efc8f0
STIX ID: report--20f43f12-e2c8-5d0d-a2b9-9b9f44efc8f0
Feed Name: securityonline.info
Sophos X-Ops observed a targeted GootLoader SEO-poisoning campaign that lured Australian Bengal cat owners to malicious search results; victims downloaded ZIP files containing JavaScript loaders that drop obfuscated payloads, create a persistent "Business Aviation" scheduled task (run via wscript.exe), and call back to attacker-controlled domains. The platform acts as an initial-access-as-a-service capable of delivering post-exploitation tools and ransomware, and evidence includes PowerShell commands sending Base64-encoded environment data and identified callhome domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
