logo

Gootloader now uses 1,000-part ZIP archives for stealthy delivery

ID: 319c164c-8081-509c-a571-ea7201a6900e

STIX ID: report--319c164c-8081-509c-a571-ea7201a6900e

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-01-15

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The report details how Gootloader operators now deliver JScript loaders using heavily malformed ZIP archives (500–1,000 concatenated parts, truncated EOCD, header mismatches, randomized fields, XOR-encoded blobs) to break common analysis tools while remaining extractable by Windows built-in utilities; the payload runs via WScript/CScript, achieves persistence with Startup .LNKs, and has been linked to initial access for ransomware deployments—Expel published detection heuristics and a YARA rule to help defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.