Threat researchers reported that Gootloader, a malware loader frequently used for initial access ahead of ransomware deployment, is being delivered in a deliberately malformed ZIP archive designed to frustrate automated inspection and analyst workflows. The archive contains a malicious JScript that initiates infection; when executed, it can spawn PowerShell to continue execution and establish persistence. The malformed ZIP causes common unpacking tools (including 7-Zip and WinRAR) to fail extraction, while the Windows built-in ZIP handler can still open the file—allowing victims to extract and run the payload while hindering defender tooling that relies on standard decompression libraries.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Expel disclosed technical details of GootLoader's first-stage delivery, explaining that the ZIP is reconstructed client-side from encoded data, uses per-download hashbusting, and abuses parser inconsistencies to evade automated analysis. The report also published defender guidance including YARA ideas, behavioral detections, and recommendations to restrict wscript/cscript and reassociate .js files away from Windows Script Host.
Reporting cited in the references linked the GootLoader developer's renewed activity to the threat actor tracked as Vanilla Tempest, which was using Rhysida ransomware. This connected the loader's return to likely rapid ransomware follow-on activity after initial access.
After resurfacing, GootLoader began using deliberately malformed ZIP archives made from roughly 500 to 1,000 concatenated ZIPs with randomized and damaged metadata. The files were engineered so common tools like 7-Zip and WinRAR often failed while Windows' built-in ZIP handler still opened them for victims.
Multiple references state that GootLoader returned in November 2025 after a period of reduced activity. The renewed campaigns featured updated delivery and execution methods designed to evade modern security controls.
One reference says active exploitation using GootLoader was observed since late 2023, with victims lured from search results to compromised WordPress sites hosting malicious ZIP files named after their queries. The infections ultimately delivered heavily obfuscated JavaScript payloads.
Reporting cited in the references says GootLoader has been evolving since at least 2020, including earlier delivery through SEO poisoning, malvertising, and compromised WordPress sites. This establishes the longer-running background of the malware loader before the newly described ZIP evasion technique.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourcerescana.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcescworld.com
Open sourceexpel.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.