logo

Gootloader | Threat Detection Overview

ID: 9f5be1ee-9c0d-5be6-94de-e544e877c8ea

STIX ID: report--9f5be1ee-9c0d-5be6-94de-e544e877c8ea

Feed Name: Huntress Blog

Threat Score
80/100

Date Published: 2025-11-05

Date Updated: 2026-04-28

...
...

Gootloader has resurfaced using novel evasion (custom WOFF2 glyph-substitution fonts and XOR-encrypted ZIP delivery via compromised WordPress comment endpoints) to deliver JavaScript that spawns PowerShell and VBScript stagers, drops Supper SOCKS5 backdoors, and enables rapid reconnaissance and lateral movement; compromised hosts are frequently handed off to Vanilla Tempest for Domain Admin acquisition and ransomware preparation, with multiple real-world cases showing Domain Controller compromise in as little as 17 hours and complete TTPs and IOCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.