Attackers operating the Gootkit loader compromised legitimate websites and used SEO poisoning to lure users searching for legal document templates into downloading malicious ZIP archives. The archives contained JavaScript that, once executed, launched obfuscated PowerShell and began a multi-stage infection chain designed to avoid writing the final payload to disk.
Trend Micro reported that the updated intrusion flow used registry stuffing, scheduled-task persistence, and reflective in-memory loading to reconstruct and run a fileless Cobalt Strike beacon. The campaign differed from earlier Gootkit activity by shifting from freeware-themed lures to legal-document themes and by encrypting registry-stored content with a custom text-replacement algorithm instead of Base64; in the observed case, the beacon communicated with 89.238.185.13 before the attack was interrupted.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The DFIR Report described a February 2023 intrusion that began with a SEO-poisoned search for an employment agreement, leading to a malicious ZIP and JavaScript file that launched Gootloader. About nine hours later the malware staged registry-resident payloads that loaded Cobalt Strike, after which the attacker moved laterally across workstations, domain controllers, and a backup server, and used a PowerShell-based SystemBC SOCKS tunnel to maintain access where beacon deployment was blocked.
Mandiant published a blog post titled "Welcome to Goot Camp: Tracking the Evolution of GOOTLOADER Operations," documenting the evolution of GOOTLOADER operations. The report represents a new public disclosure on the malware delivery framework and its operational development.
Trend Micro reported that the Gootkit loader campaign, already targeting the legal sector via SEO poisoning, had expanded to target the Australian healthcare industry using search terms such as "hospital," "health," "medical," and Australian city names. In the observed intrusion, attackers abused VLC Media Player for DLL sideloading, injected code into wabmig.exe, and created a krb.txt file containing Kerberos hashes before defenders interrupted the attack chain.
NVISO Labs published an analysis of GootLoader showing how a trojanized jQuery JavaScript file concealed obfuscated downloader logic that fetched later stages and ultimately executed a Cobalt Strike beacon entirely in memory. The report detailed the multi-stage chain using JavaScript, PowerShell, registry-stored payload components, and a .NET loader, and noted later samples changed registry paths and beacon C2 formatting.
eSentire published an analysis of Gootloader infections in which SEO poisoning and compromised websites delivered a malicious ZIP containing obfuscated JavaScript that checked Active Directory membership, retrieved registry-staged payloads, and ultimately injected IcedID into PowerShell via process hollowing. The report assessed with high confidence that operators were favoring IcedID over Cobalt Strike because it was stealthier and helped evade detection.
Sophos analyzed Gootloader as a malware delivery framework derived from techniques associated with Gootkit and REvil operators, using SEO poisoning and compromised legitimate sites to deliver malicious ZIP archives with JavaScript. The report said operators had recently used it to deploy REvil, Kronos, Gootkit, and Cobalt Strike against users in South Korea, Germany, France, and North America.
Trend Micro analyzed an intrusion in which Gootkit operators used SEO poisoning and compromised legitimate websites to lure a user searching for legal document templates into downloading a malicious ZIP archive containing JavaScript. The infection chain used obfuscated PowerShell, registry stuffing, and scheduled-task persistence to reconstruct and run a fileless Cobalt Strike payload that communicated with 89.238.185.13.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 89 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
8 references tracked. Mallory keeps watching after this page renders.
news.sophos.com
Open sourcethedfirreport.com
Open sourcemandiant.com
Open sourcetrendmicro.com
Open sourcetrendmicro.com
Open sourceblog.nviso.eu
Open sourceesentire.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.