ThreatCluster

GootLoader Malware Resurfaces Targeting WordPress Users with Font Hack

First seen 2 Dec 2025, 18:33 UTC TechradarCurrently.Att.Yahoo 27

Article Content

Browse articles
ThreatCluster

In late October 2025, GootLoader malware re-emerged after a nine-month hiatus, exploiting custom fonts to deliver malicious JavaScript. This attack primarily affects WordPress users, who are at risk of ransomware attacks due to compromised websites.