Gootloader operators compromised WordPress sites and implanted malicious PHP in theme files, plugin files, the wp_options table, and in some cases modified xmlrpc.php to selectively serve fake forum-style lure pages and malware only to filtered visitors. The infrastructure used gating based on factors such as geography, Windows user agents, logged-out status, and crawler checks, helping infected sites appear benign to most traffic. Compromised sites were observed contacting domains including my-game.biz/5.8.18.7 to redraw pages and fetch malicious ZIP archives, while altered xmlrpc.php relays forwarded victim metadata to inerino.co.za and could return obfuscated PowerShell hidden in GIF responses.
On victim systems, users commonly opened ZIP-delivered JScript files that launched via wscript.exe or cscript.exe, leading to PowerShell execution and in-memory loading of a .NET DLL. That DLL retrieved an obfuscated payload from the Windows Registry, decoded it, and executed follow-on malware including Cobalt Strike, Gootkit, and Osiris, showing Gootloader’s role as an initial access and malware delivery platform. Defenders were advised to watch for suspicious process chains involving wscript.exe, cscript.exe, powershell.exe, and rundll32.exe without arguments, and to reduce risk by changing JScript file associations and warning users about document-themed download lures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Kroll reported incidents observed in March and April 2023 in which Gootloader was delivered through business-themed SEO poisoning and fake forum pages, then established persistence and enabled follow-on deployment of Cobalt Strike and SystemBC. The intrusions involved internal reconnaissance, limited lateral movement using legitimate accounts and remote services, and exfiltration of sensitive files via FileZilla, FreeFileSync, or FTP, with no ransomware or dark-web extortion activity observed.
A January 2023 analysis described how Gootloader operators compromised WordPress sites, implanted malicious PHP in theme files, plugin files, and wp_options, and used gated fake forum lures to deliver ZIP archives containing JavaScript. It also documented newer abuse of modified xmlrpc.php files as relays that forward victim data and can blend in with legitimate XML-RPC behavior.
On 2022-12-02, eSentire escalated a GootLoader incident at a pharmaceutical company and analyzed a newer infection chain delivered via compromised WordPress sites. The observed variant created a scheduled task for persistence before contacting C2, then used PowerShell to fingerprint the host and exfiltrate the collected data through WordPress xmlrpc.php endpoints.
The Gootloader infrastructure added inerino.co.za as a new command-and-control domain around 17 November 2022. Compromised WordPress xmlrpc.php relays later forwarded victim metadata to this domain and could return obfuscated PowerShell in response.
Red Canary published analysis describing Gootloader as an initial access or delivery mechanism whose .NET DLL retrieves an obfuscated payload from the Windows Registry and executes it in memory. The report noted observed follow-on payloads including Cobalt Strike, Gootkit, and Osiris, and outlined detection and mitigation opportunities.
Sophos published research detailing how Gootloader used hundreds of compromised WordPress sites, hidden SEO poisoning, and a central 'mothership' server to profile visitors and dynamically serve fake forum pages and first-stage malware. The report described malicious PHP backdoors, WordPress hooks, and traffic filtering by Google referrer, geography, and Windows user agent.
A SentinelLabs report described a Gootloader campaign active from January through at least April 2021 that used roughly 700 compromised websites, SEO poisoning, fake forum pages, and about 900 unique JavaScript droppers to target enterprise and government users in multiple sectors. The analysis said the infection chain used Active Directory checks, fileless PowerShell stages, registry-staged payloads, and process hollowing, and assessed Gootloader as an initial-access-as-a-service platform delivering payloads including Cobalt Strike, Gootkit, Kronos, REvil, and BlueCrab.
Sophos published research describing Gootloader broadening the malware and post-compromise tooling it delivered to victims, marking an expansion beyond earlier observed payload patterns. The report framed Gootloader as an increasingly flexible delivery mechanism for additional malicious payloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcekroll.com
Open sourcegootloader.wordpress.com
Open sourceesentire.com
Open sourceredcanary.com
Open sourcelabs.sentinelone.com
Open sourcenews.sophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.