logo

Dissecting GootLoader With Node.js

ID: 189a121c-05f1-5782-960e-f8a6526a7f4f

STIX ID: report--189a121c-05f1-5782-960e-f8a6526a7f4f

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2024-07-03

Date Updated: 2026-04-28

Author: Riley Porter and Mark Lim

...
...

This Unit42 report analyzes GootLoader JavaScript malware that uses long function-array loops and counter thresholds to delay and evade sandbox analysis, details an infection chain via fake forum posts and ZIP-delivered JS, provides deobfuscated code excerpts and IOCs (SHA256 hashes), and recommends detection and response measures for affected organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.