Scmagazine
Gootloader Malware Resurgence Leads to Domain Controller Compromise
First seen 6 Nov 2025, 17:37 UTC
•
•87% similarity
•60.1
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
Recent Gootloader attacks have resulted in a Domain Controller compromise within 17 hours, as reported by Huntress. The Gootloader malware, which has been active since 2020, was previously inactive but saw a resurgence in March 2025, with multiple distinct intrusions observed last week. The malware is delivered via compromised websites using SEO poisoning techniques.
ThreatCluster AI