Scmagazine
Gootloader Malware Resurgence Leads to Domain Controller Compromise
First seen 6 Nov 2025, 17:37 UTC
•
•60.1
Export
Article Content
Browse articles
Recent Gootloader attacks have resulted in a Domain Controller compromise within 17 hours, as reported by Huntress. The Gootloader malware, which has been active since 2020, was previously inactive but saw a resurgence in March 2025, with multiple distinct intrusions observed last week. The malware is delivered via compromised websites using SEO poisoning techniques.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique
New Mistic Backdoor Linked to Ransomware Access Broker Activity
Cookeville Medical Center Data Breach Affects Over 337,000 Patients
Ransomware Attack on Berlin Senate: Data Exfiltration and Phishing Vector
Ransomware Fuels Surge in Global Cyberattacks