GootLoader Malware Resurfaces to Target WordPress Users with Font Hack
First seen 13 Nov 2025, 17:30 UTC
•
•100% similarity
•44
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
GootLoader malware reappeared in late October 2025 after a nine-month absence, targeting WordPress users. The malware is delivered through malicious JavaScript embedded in custom fonts on compromised websites, facilitating ransomware attacks.
ThreatCluster AI