Researchers detailed how the Gootkit banking trojan’s first-stage loader establishes persistence, evades analysis, and prepares browser-focused theft operations. The malware, a long-running Node.js-based threat associated with banking fraud, uses self-injection, multithreading, and runtime string decryption, then performs extensive sandbox and virtual-machine checks against filenames, environment variables, CPU identifiers, MAC prefixes, loaded modules, usernames, computer names, and BIOS-related registry values. If it detects an analysis environment, Gootkit may delete itself or sleep indefinitely; otherwise, it continues to persistence and payload retrieval.
The loader stores encrypted configuration data, recovers command-and-control settings with a simple XOR routine, and can persist either by creating a randomly named Windows service under %SystemRoot% or by abusing IEAK PendingGPOs so explorer.exe launches it without administrator rights. It also acts as an updater, sending host metadata to C2 servers over HTTP, downloading replacement executables, disabling Internet Explorer Protected Mode, and injecting decrypted x86 and x64 DLLs into browser processes via section mapping APIs. Separate reporting on a misconfigured Gootkit C2 server showed operators targeting mainly German and French bank customers with web injects, stolen-data parsers, and fraud-enabling notifications, while Microsoft published hunting guidance linking likely delivery and C2 activity to alerts involving wscript.exe, ZIP files, and JavaScript execution.

Pull IOCs and campaign context straight into your stack.
8 events from the most recent confirmed update back to the earliest known activity.
Securelist reported that Gootkit stopped operating in 2019 after a data leak and became active again in November 2020. The renewed activity marked the return of the malware family after roughly a year-long hiatus.
Securelist analyzed a Gootkit version discovered in September 2016 that used NodeJS, targeted European bank customers, and included downloader, anti-virtualization, and UAC-bypass functionality.
On April 9, 2014, Doctor Web published an analysis of BackDoor.Gootkit.112, describing it as a multi-component backdoor with bootkit capabilities that used a large Node.js-based payload and could execute remote commands. The report also detailed registry-stored payloads, process injection, and a shim-based UAC bypass using auto-elevated Windows binaries, and noted that Dr.Web added detection for the Trojan.
Multiple references state that Gootkit was originally discovered in 2014 as a banking trojan that later evolved with broader capabilities.
SentinelLabs published a follow-on analysis describing Gootkit's XOR-decrypted configuration, persistence via Windows service creation and IEAK PendingGPO abuse, C2 update logic, kill switch behavior, and browser-targeted DLL injection.
SentinelLabs published a technical analysis of Gootkit's first-stage loader covering self-injection unpacking, command-line-controlled execution paths, and extensive sandbox and VM evasion checks.
Microsoft published a Microsoft 365 Defender hunting query to detect suspected Gootkit delivery and related command-and-control activity, including wscript.exe executions involving ZIP and JavaScript command lines.
Securelist researchers exploited a configuration error on a Gootkit command-and-control server and obtained its folder tree, parsers, stolen data, bank transfer data, and logs, revealing targeting focused mainly on German and French banks.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourcelabs.sentinelone.com
Open sourcesentinelone.com
Open sourcesecurelist.com
Open sourcesecurelist.com
Open sourcegithub.com
Open sourcef5.com
Open sourcenews.drweb.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.