logo

Malformed & Dangerous: Gootloader Returns with New Ransomware Ties

ID: ecb29a1f-1a61-555b-9b25-097a08a3d554

STIX ID: report--ecb29a1f-1a61-555b-9b25-097a08a3d554

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-01-20

Date Updated: 2026-04-23

Author: Ddos

...
...

Gootloader has reemerged (reported November 2025) with updated delivery and evasion techniques: attackers are distributing a deliberately malformed ZIP to disrupt automated analysis, using NTFS 8.3 shortnames to run JavaScript via CScript which spawns chained, heavily obfuscated PowerShell instances, and collaborating with the Vanilla Tempest actor linked to Rhysida ransomware—creating an elevated ransomware risk while also exposing detection opportunities through its uncommon archive/filename behavior and process genealogy.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.