Researchers documented ongoing changes in GootLoader, a JavaScript-based initial-access malware family that infects Windows systems and is frequently linked to follow-on compromise with Cobalt Strike and ransomware. The malware is commonly distributed through SEO poisoning on compromised WordPress sites, where victims searching for agreement, contract, or form-related terms are redirected to fake forum pages and lured into downloading ZIP archives containing malicious JavaScript. When executed, the script establishes persistence with a scheduled task and uses PowerShell to beacon system information to multiple domains while awaiting additional payloads.
Analysis of newer samples showed that GootLoader altered its obfuscation and code-rearrangement logic, breaking earlier indicator-extraction workflows that relied on a single statement pattern. Researchers updated decoder logic to capture several interdependent statements, merge extracted fragments, and preserve compatibility with older variants, while separate tooling was published to statically unpack three- and six-layer GootLoader scripts and extract command-and-control data without executing the malware. The combined work highlights an active malware ecosystem in which defenders must continuously adapt detection and IOC extraction methods as GootLoader changes its JavaScript structure and delivery tradecraft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository published a static GootLoader JavaScript unpacker and C2 extractor that uses AST manipulation with Babel and avoids executing malware code. The tool supports samples with three or six layers and includes sample hashes, example output, and a C2 list for analysis.
A public write-up described GootLoader as an initial-access malware service spread through SEO poisoning on compromised WordPress blogs. It detailed the infection flow from poisoned search results to a ZIP-delivered JavaScript payload that creates persistence, contacts 10 domains, and often leads to Cobalt Strike or ransomware activity.
HP Wolf Security researchers found that changes in a newer GootLoader JavaScript sample broke their existing IOC extraction logic. They adjusted the regex pattern and added logic to merge multiple code-rearrangement statements, restoring decoding and IOC extraction for the new variant while keeping compatibility with older samples.
SophosLabs published a YARA rule named "Gootloader_JavaScript_infector" for detecting GootLoader JavaScript malware. The rule, authored by Gabor Szappanos, used five regex-based string patterns and required all of them to match.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegootloader.wordpress.com
Open sourcethreatresearch.ext.hp.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.