Gootloader Malware Evades Detection with Malformed ZIP Archives

Gootloader Malware Evades Detection with Malformed ZIP Archives

First seen 16 Jan 2026, 19:05 UTC CyberinsiderBleepingcomputerScmagazineThehackernewsRescana 84% similarity 43.9

Article Content

Browse articles
ThreatCluster

Gootloader, a malware loader used for initial access in ransomware attacks, employs a malformed ZIP archive to evade detection. This archive, which contains a JScript file, causes common unarchiving tools like 7zip and WinRAR to fail, while the default Windows utility can unpack it. This technique involves concatenating up to 1,000 archives to further complicate analysis.

ThreatCluster AI

Community

Browse all →