GootLoader is a financially motivated cybercriminal malware operation and initial-access service associated with the broader Gootkit ecosystem. Active since at least 2021, it is known for using SEO poisoning and compromised legitimate websites to deliver heavily obfuscated JavaScript payloads to enterprise and government targets. The operation has targeted high-value organizations across sectors including financial services, energy, chemicals, automotive, investment, government, and defense-related entities, with notable concentration on victims in the United States, Canada, Germany, and South Korea. GootLoader commonly relies on search-engine manipulation and socially engineered lure documents to drive victims to malicious downloads hosted through a large network of compromised websites. Its infection chains typically use multi-stage JavaScript and PowerShell execution, often with fileless elements, strong obfuscation, sandbox evasion, and geofencing. Reported tradecraft includes checking for Active Directory domain membership before continuing execution, storing payload components in the registry, and using process hollowing or related process-injection techniques to launch follow-on malware within legitimate processes. The operation functions as an access broker for other criminal actors and has been linked to delivery of post-compromise tooling and malware including Cobalt Strike, Gootkit, Kronos, REvil, and BlueCrab. It has also been described as working with Russian-based ransomware groups such as BlackCat and Rhysida. GootLoader activity has been associated with enterprise-focused intrusions and follow-on ransomware operations, making it a significant upstream threat in the cybercrime ecosystem. Known naming overlaps center on GootLoader and its relationship to Gootkit; no distinct high-confidence sub-groups are established in the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
36 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as background example of a JavaScript-centric initial access broker delivering follow-on malware.
Gootloader is referenced as returning to activity, typically known for delivering malware payloads via compromised websites and SEO poisoning.
A named threat using browser redirects or SEO poisoning to drive users to malicious content.
Gootloader is an 'Initial Access as a Service' platform that compromises high-traffic websites to deliver malicious JavaScript loaders via SEO poisoning and social engineering. It targets enterprise and government sectors, delivering a variety of malware payloads (including ransomware and infostealers) for affiliate cybercrime groups. The campaign is highly selective, using geofencing, Active Directory checks, and robust evasion techniques.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.