Gootloader operators continued to refresh their command-and-control infrastructure while maintaining a malware delivery chain built on compromised WordPress sites, fake forum pages, and malicious ZIP archives containing obfuscated JavaScript. Reporting shows the actor shifted key domains and IPs over time—from my-game.biz, inerino.co.za, and za-co-za.co.za to new-game[.]me, luckyserver777.co.za, and most recently hotheads.co.za at 91.215.85.21—with infected systems observed contacting the newest server shortly after the change. Researchers also found malicious PHP injected into WordPress files including xmlrpc.php, functions.php, 404.php, and upload paths, with additional logic hidden in the WordPress database to collect victim metadata and relay commands.
Hands-on analysis confirmed the malware remains operational despite claims it was broken: a reproduced infection on Windows 11 showed file writes, scheduled-task persistence, PowerShell execution, and outbound beaconing that encoded host-enumeration data in HTTP Cookie headers. Earlier intrusion reporting tied Gootloader to a more severe post-compromise chain in which initial JavaScript execution led to PowerShell backdoors, Cobalt Strike deployment through DLL hijacking, SystemBC use, lateral movement with remote services and PsExec, and attempts to disable Microsoft Defender. The rapid domain rotation, updated JavaScript hiding techniques, and possible dependence on newer PowerShell behavior indicate an active effort to evade detection and preserve access to Windows environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
The Gootloader operators changed command-and-control infrastructure on May 28, 2024, replacing luckyserver777.co.za with hotheads.co.za. The new domain resolved to 91.215.85.21 and infected systems were observed communicating with it within the prior 48 hours.
By February 14, 2024, infected WordPress blogs were identified using new-game.me for command-and-control communication, alongside injected PHP implants in files such as xmlrpc.php, functions.php, 404.php, and uploads paths.
A new YARA rule to detect the updated Gootloader JavaScript samples was created on February 5, 2024.
On February 4, 2024, Gootloader changed the JavaScript library it used for concealment in delivered samples.
By February 2, 2024, Microsoft Defender was detecting the majority of malicious ZIP files used in the Gootloader delivery chain.
The infrastructure analysis reported that new-game.me resolved to 91.215.85.52 on January 9, 2024, the same IP used by my-game.biz.
A historical timeline in the reporting states that Gootloader changed its command-and-control domain from za-co-za.co.za to luckyserver777.co.za in January 2024.
Around the beginning of 2024, the threat actor began changing malware download URLs constantly, apparently to hinder detection and tracking.
The Gootloader operator stood up luckyserver777.co.za as a new command-and-control server for bot communication on December 5, 2023.
Around December 2023, injected xmlrpc.php files on compromised WordPress blogs were updated to point to luckyserver777.co.za. The same analysis said the domain became resolvable to 91.215.85.69 around December 20 to December 28, 2023.
The Gootloader-linked domain new-game.me was registered on October 4, 2023, according to the infrastructure analysis.
A historical timeline states that Gootloader changed its command-and-control domain from inerino.co.za to za-co-za.co.za in July 2023.
Cybereason documented a December 2022 GootLoader incident in which SEO poisoning and compromised WordPress sites delivered malicious ZIP archives containing obfuscated JavaScript. The intrusion escalated to scheduled-task persistence, PowerShell backdoor activity, Cobalt Strike deployment, lateral movement, Defender disabling, and SystemBC use.
A historical timeline in the reporting states that Gootloader started using the command-and-control domain inerino.co.za in November 2022.
A hands-on analysis reproduced a Gootloader infection in a local Windows 11 VM, showing file writes, scheduled-task creation, PowerShell execution, and outbound beaconing with encoded enumeration data in Cookie headers. The author concluded that Gootloader was still operational and that a prior claim it was broken was incorrect.
A 2023 analysis reported that Gootloader's main C2 my-game.biz moved from Moldova-hosted infrastructure to 91.215.85.52, while inerino.co.za moved from Bulgaria to 91.215.85.53. The same report said the actor had also registered za-co-za.co.za and was referencing it in modified xmlrpc.php files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
gootloader.wordpress.com
Open sourcemalasada.tech
Open sourcegootloader.wordpress.com
Open sourcegootloader.wordpress.com
Open sourceweb.archive.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.