GootLoader Malware Resurfaces Targeting WordPress Users with Font Hack
First seen 2 Dec 2025, 18:33 UTC
•
•27
Export
Article Content
Browse articles
In late October 2025, GootLoader malware re-emerged after a nine-month hiatus, exploiting custom fonts to deliver malicious JavaScript. This attack primarily affects WordPress users, who are at risk of ransomware attacks due to compromised websites.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Gootloader Malware Resurgence Leads to Domain Controller Compromise
Gootloader Malware Resurfaces with Advanced Evasion Techniques
GootLoader Malware Resurfaces to Target WordPress Users with Font Hack
Gootloader Malware Evades Detection with Malformed ZIP Archives