GootLoader Malware Still Active, Deploys New Versions for Enhanced Attacks
ID: 838a87b6-4eab-5275-b4d5-d0af8d194862
STIX ID: report--838a87b6-4eab-5275-b4d5-d0af8d194862
Feed Name: The Hacker News
GootLoader (currently in active use as GootLoader 3) is being distributed via SEO poisoning and malicious JavaScript embedded in compromised sites and libraries to deliver follow-on payloads (Cobalt Strike, Gootkit, IcedID, REvil, SystemBC). The loader uses obfuscation, control-flow evasion, payload inflation, persistence via scheduled tasks, and has spawned related tooling (GootBot) tied to the Hive0127/UNC2565 actor; researchers (including Palo Alto Unit 42 and Cybereason) have documented techniques to analyze and bypass some anti-analysis measures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
