Scmagazine
Gootloader Malware Evades Detection with Malformed ZIP Archives
First seen 16 Jan 2026, 19:05 UTC
•



•43.9
Export
Article Content
Browse articles
Gootloader, a malware loader used for initial access in ransomware attacks, employs a malformed ZIP archive to evade detection. This archive, which contains a JScript file, causes common unarchiving tools like 7zip and WinRAR to fail, while the default Windows utility can unpack it. This technique involves concatenating up to 1,000 archives to further complicate analysis.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers
Spearphishing Campaigns Exploit Malicious Links for User Execution
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Gootloader Malware Resurgence Leads to Domain Controller Compromise
Gootloader Malware Resurfaces with Advanced Evasion Techniques
GootLoader Malware Resurfaces to Target WordPress Users with Font Hack