logo

Goot to Loot—How a Gootloader Infection Led to Credential Access

ID: 151ec84a-8af5-56d9-b425-6dcab21525e5

STIX ID: report--151ec84a-8af5-56d9-b425-6dcab21525e5

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2023-06-22

Date Updated: 2026-04-29

...
...

This ReliaQuest assessment documents a Gootloader JavaScript-based initial access campaign that delivered a SystemBC RAT, performed environment discovery and Kerberoasting, attempted LSASS credential dumping and registry hive extraction, and exfiltrated stolen credentials and artifacts to external FTP/HTTP hosts; containment actions prevented further escalation and the report provides IoCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.