Gootloader Malware Resurfaces, Compromises Domain Controllers
First seen 2 Dec 2025, 18:33 UTC
•

•90% similarity
•39.2
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Gootloader malware has re-emerged after a period of reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions, leading to domain controller compromises within 17 hours. The malware, which uses obfuscated JavaScript, is typically delivered via compromised websites and is associated with the threat actor Storm-0494.
ThreatCluster AI