GootLoader is a malware loader family used to deliver payloads to victims.
Overview
GootLoader is a malware loader family used to deliver payloads to victims. In early 2026, it adopted aggressive archive-based evasion techniques, including malformed ZIP files, hundreds to thousands of concatenated ZIP archives, and ZIP bomb tactics, to bypass security controls and complicate detection efforts.
Related Threat Clusters
-
Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers
A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…
7 articles · Updated July 1, 2026 -
Spearphishing Campaigns Exploit Malicious Links for User Execution
Recent reports detail various adversaries utilizing spearphishing tactics to exploit users into clicking malicious links. These links often lead to the execution of malware or the harvesting of sensitive information,…
2 articles · Updated September 2, 2026 -
GrayAlpha Threat Actor Uses MaskBat Loader for NetSupport RAT Deployments
Insikt Group identified GrayAlpha, a threat actor linked to FIN7, utilizing a custom loader named MaskBat to deploy NetSupport RAT through various infection vectors. These include fake browser update pages, fake 7-Zip…
2 articles · Updated August 6, 2026 -
Gootloader Malware Resurgence Leads to Domain Controller Compromise
Recent Gootloader attacks have resulted in a Domain Controller compromise within 17 hours, as reported by Huntress. The Gootloader malware, which has been active since 2020, was previously inactive but saw a resurgence…
2 articles · Updated November 6, 2025 -
Gootloader Malware Resurfaces with Advanced Evasion Techniques
Gootloader malware has reemerged as a significant threat, returning in November 2025 with enhanced capabilities to evade detection by security tools. The malware utilizes sophisticated evasion techniques, including…
3 articles · Updated January 20, 2026 -
Gootloader Malware Evades Detection with Malformed ZIP Archives
Gootloader, a malware loader used for initial access in ransomware attacks, employs a malformed ZIP archive to evade detection. This archive, which contains a JScript file, causes common unarchiving tools like 7zip and…
5 articles · Updated January 16, 2026 -
GootLoader Malware Resurfaces to Target WordPress Users with Font Hack
GootLoader malware reappeared in late October 2025 after a nine-month absence, targeting WordPress users. The malware is delivered through malicious JavaScript embedded in custom fonts on compromised websites,…
2 articles · Updated November 13, 2025 -
Gootloader Malware Resurfaces, Compromises Domain Controllers
Gootloader malware, known for delivering ransomware, has re-emerged after reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard…
2 articles · Updated November 7, 2025 -
Gootloader Malware Returns with Fake NDA Scam
Gootloader malware has resurfaced, utilizing malvertising and SEO poisoning to spread infections. Cybercriminals are employing deceptive tactics to obfuscate malware names and lure victims into scams involving fake…
2 articles · Updated January 10, 2026 -
Gootloader Malware Resurfaces, Compromises Domain Controllers
Gootloader malware has re-emerged after a period of reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions, leading to domain…
4 articles · Updated November 7, 2025
Recent Intelligence Reports
- 001 — attack.mitre.org · September 2, 2026
- T1027 — attack.mitre.org · August 7, 2026
- 012 — attack.mitre.org · July 1, 2026
- Gootloader with Low Detection Rate Bypasses Most Security Tools — Cybersecuritynews · January 20, 2026
- Gootloader Malware Maintains Low Detection Rate While Bypassing Most Security Tools — Cyberpress · January 20, 2026
- Gootloader Malware With Low Detection Rate Evades Most Security Tools — Gbhackers · January 20, 2026
- GootLoader uses malformed ZIP files to bypass security controls — Securityaffairs.Co · January 18, 2026
- GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection — Thehackernews · January 16, 2026