GootLoader Malware Resurfaces to Target WordPress Users with Font Hack
First seen 13 Nov 2025, 17:30 UTC
•
•44
Export
Article Content
Browse articles
GootLoader malware reappeared in late October 2025 after a nine-month absence, targeting WordPress users. The malware is delivered through malicious JavaScript embedded in custom fonts on compromised websites, facilitating ransomware attacks.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers
Spearphishing Campaigns Exploit Malicious Links for User Execution
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Gootloader Malware Resurgence Leads to Domain Controller Compromise
Gootloader Malware Resurfaces with Advanced Evasion Techniques
Gootloader Malware Evades Detection with Malformed ZIP Archives