Gootkit is a financially motivated cybercriminal threat actor and associated malware ecosystem commonly linked to GootLoader operations. The group is known for using GootLoader as an initial-access malware loader to deliver follow-on payloads, including Gootkit malware, Cobalt Strike, ransomware, and other post-exploitation tooling. There is no confirmed nation-state attribution. Operations are characterized by opportunistic targeting across multiple sectors, including legal, healthcare, financial, technology, manufacturing, education, and government organizations. Activity has been observed globally, with a particular focus on North America, Europe, and Australia. The actor commonly relies on SEO poisoning and malvertising to lure victims to compromised WordPress sites that deliver staged malware archives. Recent campaigns have used deeply nested and malformed concatenated ZIP archives to evade inspection and hinder analysis, followed by heavily obfuscated JavaScript payloads. Additional evasion measures have included randomized archive structures, hashbusting, custom font-based glyph substitution, and client-side decoding of encoded payload blobs. Execution typically involves script hosts such as wscript.exe and cscript.exe, with PowerShell used for follow-on activity and command-and-control support. Persistence has been established through Startup-folder shortcut creation. The actor’s tradecraft aligns with initial access, defense evasion, persistence, and post-exploitation enablement for secondary malware deployment and, in some cases, ransomware intrusion chains.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.