Skip to content

Gootloader

GootLoader is a Windows-focused malware delivery framework and initial-access malware family closely associated historically with the Gootkit ecosystem and later with ransomware intrusion activity.

Profile source: Mallory opens in a new tab

Gootloader

Family profile

GootLoader is a Windows-focused malware delivery framework and initial-access malware family closely associated historically with the Gootkit ecosystem and later with ransomware intrusion activity. It is widely used as an initial access broker capability, establishing footholds that can be handed off to follow-on operators for post-compromise actions including deployment of tools such as Cobalt Strike, GootKit, Kronos, and ransomware. Activity linked to GootLoader has been associated with actors connected to REvil and has also been observed as an access vector preceding Rhysida-related operations.

GootLoader is best known for using search-engine manipulation to lure victims to compromised or attacker-controlled web infrastructure. Campaigns have heavily abused SEO poisoning and fake forum-style or document-themed pages, especially around legal and business search terms, though later campaigns also used Google Ads and document-conversion lures. A long-running hallmark is abuse of compromised WordPress sites, where server-side implants selectively present malicious content only to intended victims based on factors such as referrer, geography, language, browser, operating system, cookies, and time-of-day, while showing benign content to researchers or non-targets.

Typical delivery involves a ZIP archive containing an obfuscated JavaScript payload. The JavaScript commonly executes through Windows script interpreters, launches PowerShell, retrieves additional stages from web infrastructure, and establishes persistence. Reported persistence mechanisms include scheduled tasks, Startup-folder shortcut chains, and Registry autoruns that invoke PowerShell. Multiple analyses describe a largely fileless multi-stage chain in which later payloads are stored in the Registry, decoded in memory, and injected or hollowed into benign processes to evade detection. GootLoader has also shown ongoing adaptation in its packaging and evasion, including hiding malicious JavaScript inside legitimate-looking libraries, rapidly rotating delivery URLs and command-and-control infrastructure, gating content, and using ZIP parsing tricks that cause different tools to display different extracted file types.

On compromised web servers, GootLoader-related WordPress implants have been observed embedded in core and theme files and in database-backed options, collecting visitor metadata and relaying commands or content from backend infrastructure. These implants support the SEO-poisoning workflow by redrawing pages, serving lure content, and brokering delivery of malicious archives.

GootLoader primarily targets Windows users and is notable less as a standalone final payload than as a resilient access platform that bridges initial compromise to broader intrusion activity. Victims have included organizations and users searching for legal, business, and other document-related content, with campaigns observed across North America, Europe, South Korea, Australia, and other regions.

Capabilities

  • Defense Evasion
  • Initial Access
  • Persistence
  • Post Exploitation
  • Process Injection

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 11, 2026
Last activity
Aug 11, 2026
Feed role
C2 / Distribution
Host form
0 IP / 2 hostnames

Leading locations

  • US2

Leading providers

  • Amazon.com, Inc.1
  • Cloudflare, Inc.1

Infrastructure traits

  • Anycast 2
  • Hosting 2

Samples

Recent associated samples

Reported operators

Threat actors

6 named in public reporting
Lure Marauder

While the Lorem Ipsum and Gootloader chains are technically distinct, the shared reliance on compromised WordPress infrastructure suggests either common access broker sources, shared compromise tooling, or operator-level coordination between the two pipelines.

Rapid Brigantine

While the Lorem Ipsum and Gootloader chains are technically distinct, the shared reliance on compromised WordPress infrastructure suggests either common access broker sources, shared compromise tooling, or operator-level coordination between the two pipelines.

Vanilla Tempest

Rhysida actors, operating under the Vanilla Tempest cluster, have used Gootloader-based access that hands off to Supper before ransomware is deployed.

Storm-0494

During the attack, Vanilla Tempest gained network access through the Storm-0494 threat actor, who infected the victim's systems with the Gootloader malware downloader.

Hive0127

GootLoader, a JavaScript-based malware loader, returned with new obfuscation techniques. It uses custom WOFF2 fonts and exploits WordPress comment sections to deliver malicious payloads.

UNC2565

GootLoader, a JavaScript-based malware loader, returned with new obfuscation techniques. It uses custom WOFF2 fonts and exploits WordPress comment sections to deliver malicious payloads.

MITRE ATT&CK

Gootloader in ATT&CK

55 distinct techniques

Techniques

55 techniques
T1547.009 Shortcut Modification T1059.007 JavaScript T1547.001 Registry Run Keys / Startup Folder T1056 Input Capture T1497.001 System Checks T1566.002 Spearphishing Link T1608.006 SEO Poisoning T1027 Obfuscated Files or Information T1036 Masquerading T1189 Drive-by Compromise T1053 Scheduled Task/Job T1059.001 PowerShell T1505.003 Web Shell T1204 User Execution T1204.002 Malicious File T1071 Application Layer Protocol T1568 Dynamic Resolution T1584 Compromise Infrastructure T1105 Ingress Tool Transfer T1041 Exfiltration Over C2 Channel T1071.001 Web Protocols T1001 Data Obfuscation T1566 Phishing T1564.001 Hidden Files and Directories T1539 Steal Web Session Cookie T1583 Acquire Infrastructure T1140 Deobfuscate/Decode Files or Information T1016 System Network Configuration Discovery T1053.005 Scheduled Task T1505 Server Software Component T1082 System Information Discovery T1078 Valid Accounts T1190 Exploit Public-Facing Application T1027.009 Embedded Payloads T1059.006 Python T1592 Gather Victim Host Information T1112 Modify Registry T1055.012 Process Hollowing T1584.004 Server T1567 Exfiltration Over Web Service T1497.003 Time Based Checks T1132 Data Encoding T1614.001 System Language Discovery T1590 Gather Victim Network Information T1037.001 Logon Script (Windows) T1583.001 Domains T1069.002 Domain Groups T1482 Domain Trust Discovery T1566.001 Spearphishing Attachment T1584.006 Web Services T1204.001 Malicious Link T1614 System Location Discovery T1584.001 Domains T1132.001 Standard Encoding T1055.002 Portable Executable Injection

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.