ThreatCluster

Gootloader Malware Resurfaces, Compromises Domain Controllers

First seen 23 Nov 2025, 03:35 UTC Theregister 92% similarity 40

Article Content

Browse articles
ThreatCluster

Gootloader malware, known for delivering ransomware, has re-emerged after reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions and domain controller compromises within 17 hours. The malware is attributed to the threat actor tracked as Storm-0494.

ThreatCluster AI

Community

Browse all →