Gootloader Malware Resurfaces in Google Ads for Legal Docs
ID: b6138a15-e483-564e-8ebe-49efa89c6add
STIX ID: report--b6138a15-e483-564e-8ebe-49efa89c6add
Feed Name: Dark Reading
Date Published: 2025-04-02
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Security researchers observed a Gootloader campaign that uses malicious Google Ads targeting legal-document searches to deliver a zipped .js payload which executes, creates scheduled tasks, and runs PowerShell to collect system data and beacon to attacker-controlled domains; known IoCs include lawliner.com and skhm.org and defenders are advised to block those URLs and search historical contacts tied to them.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
