Gootloader Malware Resurfaces, Compromises Domain Controllers

Gootloader Malware Resurfaces, Compromises Domain Controllers

First seen 2 Dec 2025, 18:33 UTC HuntressScmagazineTheregister 90% similarity 39.2

Article Content

Browse articles
ThreatCluster

Gootloader malware has re-emerged after a period of reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions, leading to domain controller compromises within 17 hours. The malware, which uses obfuscated JavaScript, is typically delivered via compromised websites and is associated with the threat actor Storm-0494.

ThreatCluster AI

Community

Browse all →