ThreatCluster

GootLoader Malware Resurfaces to Target WordPress Users with Font Hack

First seen 13 Nov 2025, 17:30 UTC TechradarCurrently.Att.Yahoo 44

Article Content

Browse articles
ThreatCluster

GootLoader malware reappeared in late October 2025 after a nine-month absence, targeting WordPress users. The malware is delivered through malicious JavaScript embedded in custom fonts on compromised websites, facilitating ransomware attacks.

Ask AI about this cluster