Gootloader Malware Resurfaces, Compromises Domain Controllers
First seen 2 Dec 2025, 18:33 UTC
•

•39.2
Export
Article Content
Browse articles
Gootloader malware has re-emerged after a period of reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions, leading to domain controller compromises within 17 hours. The malware, which uses obfuscated JavaScript, is typically delivered via compromised websites and is associated with the threat actor Storm-0494.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique
New Mistic Backdoor Linked to Ransomware Access Broker Activity
Cookeville Medical Center Data Breach Affects Over 337,000 Patients
Ransomware Attack on Berlin Senate: Data Exfiltration and Phishing Vector
Ransomware Fuels Surge in Global Cyberattacks