logo

I am Goot (Loader)

ID: cd95b7fd-d758-5c72-8902-fe5232d16c2a

STIX ID: report--cd95b7fd-d758-5c72-8902-fe5232d16c2a

Feed Name: Cybereason Blog

Threat Score
75/100

Date Published: 2024-06-25

Date Updated: 2026-04-27

Author: Cybereason Security Services Team

...
...

This Cybereason Threat Analysis examines active GootLoader operations (including GootLoader 3.0) attributed to UNC2565, describing SEO-poisoned drive-by distribution of obfuscated JavaScript leading to a three-stage execution chain (JavaScript → scheduled task → PowerShell) that performs discovery, C2 communication, and delivers post-exploitation tools such as Cobalt Strike and ransomware; the report provides technical code-level analysis, version comparisons, MITRE ATT&CK mappings, and detection/evasion details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.