Gootloader is a malware family tracked across 13 threat clusters and 19 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity July 1, 2026.
GootLoader is a malware loader family used to deliver payloads to victims. In early 2026, it adopted aggressive archive-based evasion techniques, including malformed ZIP files, hundreds to thousands of concatenated ZIP archives, and ZIP bomb tactics, to bypass security controls and complicate detection efforts.
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
Recent Gootloader attacks have resulted in a Domain Controller compromise within 17 hours, as reported by Huntress. The Gootloader malware, which has been active since 2020, was previously inactive but saw a resurgence…
Gootloader malware has reemerged as a significant threat, returning in November 2025 with enhanced capabilities to evade detection by security tools. The malware utilizes sophisticated evasion techniques, including…
Gootloader, a malware loader used for initial access in ransomware attacks, employs a malformed ZIP archive to evade detection. This archive, which contains a JScript file, causes common unarchiving tools like 7zip and…
GootLoader malware reappeared in late October 2025 after a nine-month absence, targeting WordPress users. The malware is delivered through malicious JavaScript embedded in custom fonts on compromised websites,…
Gootloader malware, known for delivering ransomware, has re-emerged after reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard…
Gootloader malware has resurfaced, utilizing malvertising and SEO poisoning to spread infections. Cybercriminals are employing deceptive tactics to obfuscate malware names and lure victims into scams involving fake…
Gootloader malware has re-emerged after a period of reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions, leading to domain…
Recent malware developments include the SesameOp backdoor utilizing OpenAI Assistants API for command and control, and advanced SSH-Tor backdoors targeting the defense sector. Additionally, Gootloader has resurfaced…
GootLoader malware utilizes malformed ZIP files composed of concatenated archives to bypass security measures. This technique has been linked to ransomware operations, including Vanilla Tempest, and is designed to evade…