Gootloader malware is back with new tricks after 7-month break
ID: 4991e77b-6a21-5428-898d-af4069913a6e
STIX ID: report--4991e77b-6a21-5428-898d-af4069913a6e
Feed Name: Bleeping Computer
The Gootloader loader campaign has resurfaced after a seven-month hiatus, using SEO-poisoned websites and malicious ads that deliver malicious JScript files inside malformed ZIP archives to install loaders and follow-on payloads (Cobalt Strike, Supper SOCKS5 backdoor). Researchers observed evasion techniques—glyph-swapped web fonts to hide keywords in HTML and ZIP malformedness that yields different extraction results across tools—facilitating initial access for ransomware affiliates and rapid domain compromise across numerous compromised sites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
