Gootloader malware has re-emerged after a period of inactivity, deploying new techniques to compromise victims through SEO poisoning and malicious JavaScript injected into compromised or attacker-controlled websites. Recent attacks observed by Huntress and other researchers show Gootloader being used to gain initial access to corporate networks, with one incident resulting in a Domain Controller compromise within 17 hours. The loader, operated by the threat actor Storm-0494, provides access to Vanilla Tempest, which then deploys backdoors such as the Supper SOCKS5 and ultimately delivers ransomware, including the Rhysida family. The infection chain leverages obfuscated JavaScript, custom WOFF2 fonts, and XOR-encrypted ZIP archives, with payloads tailored to evade static analysis and exfiltrate sensitive information from active user sessions.
The distribution method relies heavily on SEO poisoning, where fake legal document and agreement template sites are promoted in search results, enticing users to download malicious files. Once executed, Gootloader runs PowerShell scripts to enumerate environment variables, running processes, and desktop files, sending this data to hardcoded C2 servers. The operation's infrastructure has been actively targeted by security researchers, leading to a temporary cessation in March 2025, but the campaign has since resumed with new tricks and payloads, including Cobalt Strike and various backdoors. The renewed activity highlights the persistent threat posed by Gootloader and its affiliates, who continue to refine their tactics to evade detection and maximize impact on targeted organizations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The renewed intrusions included rapid deployment of the Supper SOCKS5 backdoor for persistence and remote access. Huntress also linked the TextShell obfuscator to both Supper and OysterLoader samples associated with Vanilla Tempest.
Huntress assessed that Storm-0494 used Gootloader for initial access and then handed victims to the Vanilla Tempest operation for follow-on intrusion activity. The observed tooling and behavior were consistent with preparation for Rhysida ransomware deployment.
In two of the three observed incidents, the activity quickly progressed into hands-on-keyboard attacks, with one Windows Domain Controller compromised in 16 hours and 54 minutes. The post-compromise activity included Active Directory reconnaissance, Kerberoasting, lateral movement via WinRM, and privileged account creation.
Huntress reported seeing three Gootloader intrusions during the week prior to November 6, 2025. In at least one case, a user was infected after visiting a malicious search result tied to a compromised website.
In the renewed campaign, attackers abused WordPress comment submission endpoints to deliver XOR-encrypted ZIP payloads and used a custom WOFF2 font to disguise malicious filenames. The infections were delivered through compromised websites, including SEO-poisoned pages that ranked in Bing search results.
Huntress observed Gootloader activity resume starting on October 27, 2025, after roughly a seven-month break. The renewed campaign used SEO poisoning and compromised WordPress sites to lure victims into downloading malicious JavaScript.
After a period of reduced activity, Gootloader briefly resurfaced in March 2025 before going largely quiet again. This marked the only notable activity prior to the later fall 2025 wave described by Huntress.
Gootloader, a JavaScript-based malware family used for initial access and malware delivery, was first seen in 2020. It later became associated with intrusion chains that can lead to ransomware deployment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.