Gootloader Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
19
occurrences
First Seen
November 6, 2025
Last Seen
July 1, 2026

Gootloader is a malware family tracked across 13 threat clusters and 19 intelligence report mentions on ThreatCluster. First observed November 6, 2025; most recent activity July 1, 2026.

Overview

GootLoader is a malware loader family used to deliver payloads to victims. In early 2026, it adopted aggressive archive-based evasion techniques, including malformed ZIP files, hundreds to thousands of concatenated ZIP archives, and ZIP bomb tactics, to bypass security controls and complicate detection efforts.

Related Threat Clusters

  • Widespread Abuse of ScreenConnect to Deploy AsyncRAT via Fake Installers

    A significant cybersecurity campaign has emerged, exploiting the legitimate remote access tool ScreenConnect to deploy AsyncRAT malware. Attackers utilized spoofed websites and typosquatted domains, masquerading as…

    7 articles · Updated July 1, 2026
  • Gootloader Malware Resurgence Leads to Domain Controller Compromise

    Recent Gootloader attacks have resulted in a Domain Controller compromise within 17 hours, as reported by Huntress. The Gootloader malware, which has been active since 2020, was previously inactive but saw a resurgence…

    2 articles · Updated November 6, 2025
  • Gootloader Malware Resurfaces with Advanced Evasion Techniques

    Gootloader malware has reemerged as a significant threat, returning in November 2025 with enhanced capabilities to evade detection by security tools. The malware utilizes sophisticated evasion techniques, including…

    3 articles · Updated January 20, 2026
  • Gootloader Malware Evades Detection with Malformed ZIP Archives

    Gootloader, a malware loader used for initial access in ransomware attacks, employs a malformed ZIP archive to evade detection. This archive, which contains a JScript file, causes common unarchiving tools like 7zip and…

    5 articles · Updated January 16, 2026
  • GootLoader Malware Resurfaces to Target WordPress Users with Font Hack

    GootLoader malware reappeared in late October 2025 after a nine-month absence, targeting WordPress users. The malware is delivered through malicious JavaScript embedded in custom fonts on compromised websites,…

    2 articles · Updated November 13, 2025
  • Gootloader Malware Resurfaces, Compromises Domain Controllers

    Gootloader malware, known for delivering ransomware, has re-emerged after reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard…

    2 articles · Updated November 7, 2025
  • Gootloader Malware Returns with Fake NDA Scam

    Gootloader malware has resurfaced, utilizing malvertising and SEO poisoning to spread infections. Cybercriminals are employing deceptive tactics to obfuscate malware names and lure victims into scams involving fake…

    2 articles · Updated January 10, 2026
  • Gootloader Malware Resurfaces, Compromises Domain Controllers

    Gootloader malware has re-emerged after a period of reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions, leading to domain…

    4 articles · Updated November 7, 2025
  • Emerging Malware Threats Targeting Defense and Software Systems

    Recent malware developments include the SesameOp backdoor utilizing OpenAI Assistants API for command and control, and advanced SSH-Tor backdoors targeting the defense sector. Additionally, Gootloader has resurfaced…

    2 articles · Updated November 9, 2025
  • GootLoader Exploits Malformed ZIP Files to Evade Detection

    GootLoader malware utilizes malformed ZIP files composed of concatenated archives to bypass security measures. This technique has been linked to ransomware operations, including Vanilla Tempest, and is designed to evade…

    2 articles · Updated January 18, 2026

Recent Intelligence Reports

  • 012 — attack.mitre.org · July 1, 2026
  • Gootloader with Low Detection Rate Bypasses Most Security Tools — Cybersecuritynews · January 20, 2026
  • Gootloader Malware Maintains Low Detection Rate While Bypassing Most Security Tools — Cyberpress · January 20, 2026
  • Gootloader Malware With Low Detection Rate Evades Most Security Tools — Gbhackers · January 20, 2026
  • GootLoader uses malformed ZIP files to bypass security controls — Securityaffairs.Co · January 18, 2026
  • GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection — Thehackernews · January 16, 2026
  • How Gootloader uses malformed ZIP archives to evade detection — Scmagazine · January 16, 2026
  • Gootloader now uses 1,000 — Bleepingcomputer · January 15, 2026

CVSS v3.1 Breakdown