Gootloader Malware Resurfaces, Compromises Domain Controllers
First seen 23 Nov 2025, 03:35 UTC
•
•92% similarity
•40
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Gootloader malware, known for delivering ransomware, has re-emerged after reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions and domain controller compromises within 17 hours. The malware is attributed to the threat actor tracked as Storm-0494.
ThreatCluster AI