Gootloader Malware Resurgence Leads to Domain Controller Compromise

Gootloader Malware Resurgence Leads to Domain Controller Compromise

First seen 6 Nov 2025, 17:37 UTC HuntressScmagazine 87% similarity 60.1

Article Content

Browse articles
ThreatCluster

Recent Gootloader attacks have resulted in a Domain Controller compromise within 17 hours, as reported by Huntress. The Gootloader malware, which has been active since 2020, was previously inactive but saw a resurgence in March 2025, with multiple distinct intrusions observed last week. The malware is delivered via compromised websites using SEO poisoning techniques.

ThreatCluster AI

Community

Browse all →