Gootloader is a JavaScript-based malware delivery framework and initial-access malware operation used to compromise Windows enterprise environments and deliver follow-on payloads including Gootkit, IcedID, Cobalt Strike, Kronos, REvil, and other intrusion tooling. It is widely associated with search-engine poisoning campaigns that lure victims searching for business, legal, or contract-related topics to compromised websites, especially compromised WordPress infrastructure, where fake forum-style pages offer ZIP archives containing malicious JavaScript files named to match the victim’s query. The operation has been characterized as Malware-as-a-Service and Initial Access as a Service because it functions primarily as a distribution and access broker for downstream malware and affiliate intrusion activity.
The infection chain typically begins with SEO poisoning and a landing page on a compromised website. After the victim downloads and executes the JavaScript payload through Windows Script Host, Gootloader runs a heavily obfuscated multi-stage chain that may use additional JavaScript, PowerShell, and registry-resident components. The malware commonly fingerprints the host, including checking whether the system is joined to an Active Directory domain, and selectively retrieves later stages only for desirable enterprise targets. Observed variants have used compromised web infrastructure and WordPress endpoints for command-and-control and host profiling.
Gootloader is designed to minimize disk artifacts and evade detection. Reported behaviors include layered JavaScript obfuscation, delayed execution, in-memory staging, storage of encoded payloads in the Windows registry, scheduled-task persistence, and process hollowing into legitimate Windows processes. Some variants establish persistence immediately, while others first contact remote infrastructure and then stage additional components. Newer variants have also been observed collecting detailed host information such as processes, operating system data, environment variables, desktop items, and drive information, then transmitting that data to help operators decide whether to deploy additional malware.
Post-compromise activity linked to Gootloader infections includes deployment of Cobalt Strike and SystemBC, credential access, LDAP and Active Directory discovery, lateral movement via SMB, WMI, WinRM, remote services, and RDP, as well as exfiltration of sensitive files in some incidents. Targeting has included business professionals and organizations in sectors such as legal services, healthcare, finance, pharmaceutical, energy, automotive, military, and government across North America, Europe, and parts of Asia. Gootloader remains notable for combining effective social-engineering lures, compromised legitimate websites, selective enterprise targeting, and fileless staging to provide reliable initial access for financially motivated intrusion operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
During the month of December 2022, the Cybereason Incident Response (IR) team investigated an incident which involved new deployment methods of GootLoader... GootLoader targets companies in English-speaking countries... targeted attacks have been more prominent against healthcare and finance organizations.
While the Lorem Ipsum and Gootloader chains are technically distinct, the shared reliance on compromised WordPress infrastructure suggests either common access broker sources, shared compromise tooling, or operator-level coordination between the two pipelines.
While the Lorem Ipsum and Gootloader chains are technically distinct, the shared reliance on compromised WordPress infrastructure suggests either common access broker sources, shared compromise tooling, or operator-level coordination between the two pipelines.
Rhysida actors, operating under the Vanilla Tempest cluster, have used Gootloader-based access that hands off to Supper before ransomware is deployed.
During the attack, Vanilla Tempest gained network access through the Storm-0494 threat actor, who infected the victim's systems with the Gootloader malware downloader.
GootLoader, a JavaScript-based malware loader, returned with new obfuscation techniques. It uses custom WOFF2 fonts and exploits WordPress comment sections to deliver malicious payloads.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
Gootloader is a Malware-as-a-Service (MaaS) offering that is spread through Search Engine Optimization (SEO) poisoning to distribute malicious payloads, such as IcedID.
eSentire’s security research team, (TRU), discovered in early January that the threat group behind the malware downloader, Gootloader, had compromised dozens of legitimate websites across the globe.
These attacks come directly on the heels of an extensive and well-planned Drive-By-Download Campaign ... launched in late December. This malicious campaign’s sole purpose is to infect business professionals’ computer systems with the Sodin ransomware, the Gootkit banking trojan or the Cobalt Strike intrusion tool.
In some cases, we have observed the scheduled task is created as a persistence mechanism to decode the registry values
TRU found that Gootloader consisted of heavily obfuscated JavaScript code.
In some cases, we have observed the scheduled task is created as a persistence mechanism to decode the registry values
eSentire’s Security Operations Center (SOC) observed malicious code being written to the Windows Registry – a common, fileless malware tactic.
Gootloader maintains persistence on a blog, by adding PHP code to various files, typically in the themes directory, but have also seen it in the plugins directory. | Additionally, stored in the “wp_options” table, is base64 encoded PHP code is stored, this combination allows them to remotely run PHP code.
TRU found that Gootloader consisted of heavily obfuscated JavaScript code. It was compressed to bypass automated security appliances.
rule Gootloader_JavaScript_infector ... strings: $a1 ... $a2 ... $a3 ... $a4 ...
eSentire’s Security Operations Center (SOC) observed malicious code being written to the Windows Registry – a common, fileless malware tactic.
One of the top search results is a web page, made to look like a forum question/answer (Q/A) page, that references a link to a sample agreement for PAs working in California.
Gootloader is using a process hollowing technique to inject IcedID loader into PowerShell processes.
The script checks if the infected host is a part of the Active Directory domain by using the environment variable %USERDNSDOMAIN%
Indicators of Compromise ... jonathanbartz[.]com Command and Control
268 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
116 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a loader / initial access malware associated with access brokerage used to help obtain initial access for INC Ransom operations.
Malware/loader used in SEO-poisoning campaigns via compromised WordPress sites and fake forum pages offering legal or business document templates; used to gain initial footholds that are then sold to ransomware operators.
Gootloader2
A loader used for initial access in Rhysida intrusions, handing off to Supper before ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.