Goot to LootâHow a Gootloader Infection Led to Credential Access
ID: 151ec84a-8af5-56d9-b425-6dcab21525e5
STIX ID: report--151ec84a-8af5-56d9-b425-6dcab21525e5
Feed Name: ReliaQuest Blog
Threat Score
This ReliaQuest assessment documents a Gootloader JavaScript-based initial access campaign that delivered a SystemBC RAT, performed environment discovery and Kerberoasting, attempted LSASS credential dumping and registry hive extraction, and exfiltrated stolen credentials and artifacts to external FTP/HTTP hosts; containment actions prevented further escalation and the report provides IoCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
