Skip to main content
Mallory
MalwareRansomwareUsed by 1 actor

GootKit

GootKit is a banking Trojan that also functions as an information stealer and remote access Trojan (RAT). The provided content describes it as highly evasive and capable of establishing a persistent foothold on victim systems, enabling follow-on exploitation including deployment of Cobalt Strike, ransomware, and other tooling. It has also been referenced as an e-banking Trojan and associated with HVNC-style fraud activity in broader banking-malware tradecraft.

The malware is closely associated with GootLoader delivery chains. Multiple sources in the content state that GootLoader historically loaded GootKit, and recent investigations describe first-stage obfuscated JavaScript downloaded via SEO poisoning and trojanized search-engine results, often from compromised websites, leading to second-stage JavaScript associated with GootKit. In one 2024 case, a malicious ZIP downloaded from a compromised site contained a JavaScript payload that dropped a larger script under AppData\Roaming\Notepad++, created scheduled-task persistence, executed via WScript/CScript, and spawned PowerShell. Network behavior included HTTP requests to multiple domains at /xmlrpc.php with Base64-encoded host enumeration data, including USERNAME and USERDOMAIN values. Sophos classified related artifacts as JS/Drop-DIJ and JS/Gootkit-AW. Example observed artifacts included the URL hxxps://ledabel[.]be/en/are-bengal-cats-legal-in-australia-understanding-the-laws-and-regulations/, redirect to hxxps://www[.]chanderbhushan[.]com/doc[.]php, ZIP file Are_bengal_cats_legal_in_australia_33924.zip, dropped script paths under C:\Users<Username>\AppData\Roaming\Notepad++, and scheduled task names such as Business Aviation and Destination Branding.

The content also ties GootKit to criminal distribution ecosystems. Storm-0324 has distributed GootKit as a first-stage payload since at least 2016 alongside other malware families, using phishing and exploit-kit-based delivery chains. Microsoft notes detections including Trojan:Win32/Gootkit. Other content states criminal operators have used the Cutwail spambot and the RIG and Nebula exploit kits to distribute GootKit, and that developers/operators updated configuration files to improve targeting and expanded target lists for video-capture capability in 2017. Emotet has also been observed delivering GootKit as a third-party payload.

High-confidence behaviors and characteristics directly mentioned in the content include: banking credential theft/e-banking fraud functionality; info-stealing and RAT capability; persistence establishment; use in multi-stage JavaScript and PowerShell infection chains; scheduled-task persistence; host enumeration and outbound C2/call-home traffic; and use as a precursor or enabler for later ransomware activity. Targeting in the provided material is opportunistic rather than sector-specific, though GootLoader-linked campaigns delivering GootKit have affected sectors including legal, healthcare, financial, technology, manufacturing, education, and government, with activity observed globally and specifically in North America, Europe, and Australia.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Storm-0324

Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Gootkit, a banking trojan

via microsoft generalmicrosoft.com
MITRE ATT&CK

Techniques & procedures

10 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583Acquire InfrastructureEvidence1

Gootkit relies on trojanized search engine optimization (SEO) social engineering techniques, similar to Yellow Cockatoo.

T1608.006SEO PoisoningEvidence1

GootLoader is known for using search engine optimization (SEO) poisoning for its initial access... the new variant was found to be using SEO poisoning... to deliver the new, JavaScript-based Gootloader package.

Initial Access

2 techniques
T1189Drive-by CompromiseEvidence1

Storm-0324 manages a malware distribution chain and has used exploit kit and email-based vectors to deliver malware payloads.

T1566PhishingEvidence1

Storm-0324’s delivery chain begins with phishing emails referencing invoices or payments and containing a link to a SharePoint site that hosts a ZIP archive.

Execution

2 techniques
T1053.005Scheduled TaskEvidence1

We additionally observed the creation of a scheduled task named “Business Aviation”... This was suspected to be a persistence method... Persistence was obtained via CScript.exe executing the file SMALLU~1.js via a scheduled task named Destination Branding.

T1059.007JavaScriptEvidence1
TacticExecution

Upon review of the running processes, we were able to determine that a small JavaScript file was dropping a large JavaScript file... We additionally observed the creation of a scheduled task named “Business Aviation” with the command line “wscript REHABI~1.JS”.

Persistence

1 technique
T1053.005Scheduled TaskEvidence1

We additionally observed the creation of a scheduled task named “Business Aviation”... This was suspected to be a persistence method... Persistence was obtained via CScript.exe executing the file SMALLU~1.js via a scheduled task named Destination Branding.

T1053.005Scheduled TaskEvidence1

We additionally observed the creation of a scheduled task named “Business Aviation”... This was suspected to be a persistence method... Persistence was obtained via CScript.exe executing the file SMALLU~1.js via a scheduled task named Destination Branding.

Stealth

1 technique
T1027Obfuscated Files or InformationEvidence1
TacticStealth

With the obfuscated Javascript and VB Script samples... The JS Stage includes a few unused variables, entangled functions and scrambled strings.

Discovery

1 technique
T1082System Information DiscoveryEvidence1
TacticDiscovery

The requests contained Base64-encoded cookies which, when decoded, showed enumeration information regarding device directories and host information... the process would read USERNAME and USER DOMAIN information and send the data to the URIs.

T1071Application Layer ProtocolEvidence1

Spamhaus researchers issued listings for over 7,000 botnet Command & Control ("C&C") servers... These C&C servers enabled and controlled online crime such as credential theft, e-banking fraud, spam and DDoS attacks. They were also used for the retrieval of stolen data.

Exfiltration

1 technique
T1567Exfiltration Over Web ServiceEvidence1

FakeNet showed various domain names being reached out to with GET /xmlrpc.php HTTP/1.1 requests via Powershell.exe. The requests contained Base64-encoded cookies... showing enumeration information regarding device directories and host information.

INDICATORS OF COMPROMISE

IOCs tracked for this family

7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
5 tracked

IPs, domains, and DNS infrastructure linked to this family.

Other
2 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app5 months ago
domain●●●●●●●●●●●●View more in app5 months ago
domain●●●●●●●●●●●●View more in app5 months ago
uri●●●●●●●●●●●●View more in app5 months ago
uri●●●●●●●●●●●●View more in app5 months ago
domain●●●●●●●●●●●●View more in app5 months ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching7

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping10

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.