Scmagazine
Gootloader Malware Evades Detection with Malformed ZIP Archives
First seen 16 Jan 2026, 19:05 UTC
•



•84% similarity
•43.9
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Gootloader, a malware loader used for initial access in ransomware attacks, employs a malformed ZIP archive to evade detection. This archive, which contains a JScript file, causes common unarchiving tools like 7zip and WinRAR to fail, while the default Windows utility can unpack it. This technique involves concatenating up to 1,000 archives to further complicate analysis.
ThreatCluster AI