Skip to content

GootKit

Gootkit is a Windows banking trojan and modular malware platform first identified in 2014.

Profile source: Mallory opens in a new tab

GootKit

Family profile

Gootkit is a Windows banking trojan and modular malware platform first identified in 2014. It began as a banking-focused threat and later expanded into a broader information-stealing and post-compromise framework. The malware is notable for a multi-stage architecture that combines a native loader with a JavaScript-based main body executed through an embedded Node.js runtime, as well as extensive anti-analysis and anti-virtualization logic intended to frustrate sandboxing and reverse engineering.

Gootkit has historically been used to steal browser data and authentication material, collect cookies, capture keystrokes, take screenshots, and perform form grabbing and web-injection activity associated with man-in-the-browser operations. It has also been observed modifying browser traffic and patching certificate-validation logic inside targeted browser processes to facilitate interception and manipulation of encrypted sessions. Reported browser targets include major Chromium-based browsers, Firefox, Internet Explorer, Edge, Opera, and Safari on Windows. The malware communicates with command-and-control infrastructure using custom packet formats and supports exfiltration of credentials, logs, screenshots, active-window data, and other victim information.

The loader component uses staged decryption and in-memory execution, including shellcode-based unpacking and browser-focused code injection. It employs anti-debugging and anti-VM checks and may stall indefinitely when it detects analysis environments. Persistence has been achieved through Windows service creation and abuse of policy-related mechanisms. Gootkit has also been associated with browser-process injection and broader defense-evasion tradecraft.

Distribution has evolved over time. Early campaigns used spam and exploit kits, while later activity relied heavily on compromised websites, fake forum pages, and SEO poisoning to lure victims into downloading JavaScript-based loaders. GootLoader has been widely described as the initial-access framework used to deliver Gootkit and other follow-on payloads, making Gootkit part of a broader criminal delivery ecosystem. Campaigns linked to GootLoader and related infrastructure have targeted business users and sectors including legal, government, finance, healthcare, automotive, pharmaceutical, energy, and other enterprises, with significant victimization reported in Europe and North America.

Gootkit has also appeared in multi-malware operations and has been delivered by or alongside other criminal services and malware families. It has been referenced as a downstream payload in campaigns involving loaders and botnets such as Emotet, and it has been associated with financially motivated cybercrime activity targeting banking customers and enterprise environments. Its long-running use, modular design, and integration with web-injection and credential-theft workflows make it a significant banking-trojan family in the Windows threat landscape.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Keylogging
  • Persistence
  • Process Injection

Reported operators

Threat actors

3 named in public reporting
TA554

We have observed final payloads including Ramnit, Gootkit, DarkVNC, Ursnif, and PsiXBot.

TA547

Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.

Storm-0324

Storm-0324 has distributed a range of first-stage payloads since at least 2016, including: ... Gootkit, a banking trojan

MITRE ATT&CK

GootKit in ATT&CK

59 distinct techniques

Techniques

59 techniques
T1189 Drive-by Compromise T1071 Application Layer Protocol T1105 Ingress Tool Transfer T1112 Modify Registry T1622 Debugger Evasion T1547 Boot or Logon Autostart Execution T1056.001 Keylogging T1059.007 JavaScript T1543.003 Windows Service T1055 Process Injection T1555 Credentials from Password Stores T1556 Modify Authentication Process T1539 Steal Web Session Cookie T1113 Screen Capture T1027 Obfuscated Files or Information T1140 Deobfuscate/Decode Files or Information T1566 Phishing T1497.001 System Checks T1185 Browser Session Hijacking T1497 Virtualization/Sandbox Evasion T1059.001 PowerShell T1566.002 Spearphishing Link T1204.002 Malicious File T1497.003 Time Based Checks T1568.002 Domain Generation Algorithms T1566.001 Spearphishing Attachment T1012 Query Registry T1059 Command and Scripting Interpreter T1059.005 Visual Basic T1203 Exploitation for Client Execution T1190 Exploit Public-Facing Application T1068 Exploitation for Privilege Escalation T1071.001 Web Protocols T1489 Service Stop T1620 Reflective Code Loading T1562.001 Disable or Modify Tools T1583 Acquire Infrastructure T1057 Process Discovery T1005 Data from Local System T1548.002 Bypass User Account Control T1608.006 SEO Poisoning T1033 System Owner/User Discovery T1056 Input Capture T1053 Scheduled Task/Job T1132 Data Encoding T1055.002 Portable Executable Injection T1218.014 MMC T1070.004 File Deletion T1082 System Information Discovery T1547.001 Registry Run Keys / Startup Folder T1053.005 Scheduled Task T1592 Gather Victim Host Information T1505.003 Web Shell T1027.009 Embedded Payloads T1078 Valid Accounts T1505 Server Software Component T1055.012 Process Hollowing T1567 Exfiltration Over Web Service T1059.006 Python

Reporting

Research mentioning GootKit

Jul 17
Sentinelone

Gootkit Banking Trojan | Part 2: Persistence & Other Capabilities - SentinelLabs

Researchers detailed how the Gootkit banking trojan’s first-stage loader establishes persistence, evades analysis, and prepares browser-focused theft operations. The malware, a long-running Node.js-based threat associated with banking fraud, uses self-injection, multithreading, and runtime string decryption, then performs extensive sandbox and virtual-machine checks against filenames, environment variables, CPU identifiers, MAC prefixes, loaded modules, usernames, computer names, and BIOS-related registry values. If it detects an analysis environment, Gootkit may delete itself or sleep indefinitely; otherwise, it continues to persistence and payload retrieval. The loader stores encrypted configuration data, recovers command-and-control settings with a simple XOR routine, and can persist either by creating a randomly named Windows service under %SystemRoot% or by abusing IEAK PendingGPOs so explorer.exe launches it without administrator rights. It also acts as an updater, sending host metadata to C2 servers over HTTP, downloading replacement executables, disabling Internet Explorer Protected Mode, and injecting decrypted x86 and x64 DLLs into browser processes via section mapping APIs. Separate reporting on a misconfigured Gootkit C2 server showed operators targeting mainly German and French bank customers with web injects, stolen-data parsers, and fraud-enabling notifications, while Microsoft published hunting guidance linking likely delivery and C2 activity to alerts involving wscript.exe, ZIP files, and JavaScript execution.

Jan 1
Sophos Threat Research

“Gootloader” expands its payload delivery options | SOPHOS

Attackers operating the Gootkit loader compromised legitimate websites and used SEO poisoning to lure users searching for legal document templates into downloading malicious ZIP archives. The archives contained JavaScript that, once executed, launched obfuscated PowerShell and began a multi-stage infection chain designed to avoid writing the final payload to disk. Trend Micro reported that the updated intrusion flow used registry stuffing, scheduled-task persistence, and reflective in-memory loading to reconstruct and run a fileless Cobalt Strike beacon. The campaign differed from earlier Gootkit activity by shifting from freeware-themed lures to legal-document themes and by encrypting registry-stored content with a custom text-replacement algorithm instead of Base64; in the observed case, the beacon communicated with 89.238.185.13 before the attack was interrupted.

Jan 1
Zscaler Com Other

Targeted Attack Leverages India-China Border Dispute

Researchers documented targeted intrusion campaigns that used military and geopolitical decoy documents to compromise victims in South Asia and deploy Cobalt Strike. Cisco Talos reported that attackers distributed malicious Microsoft Office files posing as Indian Air Force and other government or military documents, with macros dropping a custom loader called IndigoDrop into the Windows Startup folder for persistence. IndigoDrop performed anti-infection checks, fetched Metasploit shellcode, and ultimately loaded an XOR-encoded Cobalt Strike beacon hidden in trojanized jQuery files, while related Python modules conducted reconnaissance and stole browser and Wi-Fi credentials. A separate campaign analyzed by Zscaler used a Word document themed around the India-China border dispute to trigger a macro-delivered PowerShell chain that staged shellcode behind a fake GIF header and installed a Cobalt Strike beacon over HTTPS. The operators used fileless techniques, spoofed HTTP Host headers such as update.windows.microsoft.com, and in some variants injected an RSA-encrypted payload into notepad.exe; researchers also identified infrastructure including 47.240.73.77, 114.67.110.37, and 360doc.com-based command-and-control domains. Across both campaigns, the attackers relied on topical military lures, multi-stage loaders, and legitimate-looking web traffic to conceal remote access activity against likely government and defense-related targets.

Feb 26
Dfir Report

SEO Poisoning to Domain Control: The Gootloader Saga Continues - The DFIR Report

Jan 26
Mandiant

Welcome to Goot Camp: Tracking the Evolution of GOOTLOADER Operations

Jan 9
Trend Micro Research

Gootkit Loader Actively Targets Australian Healthcare Industry | Trend Micro (US)

Sep 23
Sentinelone

Gootkit Banking Trojan | Deep Dive into Anti-Analysis Features - SentinelLabs

Jul 27
Trend Micro Research

Gootkit Loader’s Updated Tactics and Fileless Delivery of Cobalt Strike | Trend Micro (US)

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.