Gootloader now uses 1,000-part ZIP archives for stealthy delivery
ID: 319c164c-8081-509c-a571-ea7201a6900e
STIX ID: report--319c164c-8081-509c-a571-ea7201a6900e
Feed Name: Bleeping Computer
The report details how Gootloader operators now deliver JScript loaders using heavily malformed ZIP archives (500–1,000 concatenated parts, truncated EOCD, header mismatches, randomized fields, XOR-encoded blobs) to break common analysis tools while remaining extractable by Windows built-in utilities; the payload runs via WScript/CScript, achieves persistence with Startup .LNKs, and has been linked to initial access for ransomware deployments—Expel published detection heuristics and a YARA rule to help defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
