logo

GootLoader Malware Still Active, Deploys New Versions for Enhanced Attacks

ID: 838a87b6-4eab-5275-b4d5-d0af8d194862

STIX ID: report--838a87b6-4eab-5275-b4d5-d0af8d194862

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-07-05

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

GootLoader (currently in active use as GootLoader 3) is being distributed via SEO poisoning and malicious JavaScript embedded in compromised sites and libraries to deliver follow-on payloads (Cobalt Strike, Gootkit, IcedID, REvil, SystemBC). The loader uses obfuscation, control-flow evasion, payload inflation, persistence via scheduled tasks, and has spawned related tooling (GootBot) tied to the Hive0127/UNC2565 actor; researchers (including Palo Alto Unit 42 and Cybereason) have documented techniques to analyze and bypass some anti-analysis measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.