Gootloader Malware Resurfaces, Compromises Domain Controllers
First seen 23 Nov 2025, 03:35 UTC
•
•40
Export
Article Content
Browse articles
Gootloader malware, known for delivering ransomware, has re-emerged after reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions and domain controller compromises within 17 hours. The malware is attributed to the threat actor tracked as Storm-0494.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique
New Mistic Backdoor Linked to Ransomware Access Broker Activity
Cookeville Medical Center Data Breach Affects Over 337,000 Patients
Ransomware Attack on Berlin Senate: Data Exfiltration and Phishing Vector
Ransomware Fuels Surge in Global Cyberattacks