Last seven days
- First activity
- Aug 11, 2026
- Last activity
- Aug 11, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 2 hostnames
GootLoader is a Windows-focused malware delivery framework and initial-access malware family closely associated historically with the Gootkit ecosystem and later with ransomware intrusion activity.
Profile source: Mallory opens in a new tabGootloader
GootLoader is a Windows-focused malware delivery framework and initial-access malware family closely associated historically with the Gootkit ecosystem and later with ransomware intrusion activity. It is widely used as an initial access broker capability, establishing footholds that can be handed off to follow-on operators for post-compromise actions including deployment of tools such as Cobalt Strike, GootKit, Kronos, and ransomware. Activity linked to GootLoader has been associated with actors connected to REvil and has also been observed as an access vector preceding Rhysida-related operations.
GootLoader is best known for using search-engine manipulation to lure victims to compromised or attacker-controlled web infrastructure. Campaigns have heavily abused SEO poisoning and fake forum-style or document-themed pages, especially around legal and business search terms, though later campaigns also used Google Ads and document-conversion lures. A long-running hallmark is abuse of compromised WordPress sites, where server-side implants selectively present malicious content only to intended victims based on factors such as referrer, geography, language, browser, operating system, cookies, and time-of-day, while showing benign content to researchers or non-targets.
Typical delivery involves a ZIP archive containing an obfuscated JavaScript payload. The JavaScript commonly executes through Windows script interpreters, launches PowerShell, retrieves additional stages from web infrastructure, and establishes persistence. Reported persistence mechanisms include scheduled tasks, Startup-folder shortcut chains, and Registry autoruns that invoke PowerShell. Multiple analyses describe a largely fileless multi-stage chain in which later payloads are stored in the Registry, decoded in memory, and injected or hollowed into benign processes to evade detection. GootLoader has also shown ongoing adaptation in its packaging and evasion, including hiding malicious JavaScript inside legitimate-looking libraries, rapidly rotating delivery URLs and command-and-control infrastructure, gating content, and using ZIP parsing tricks that cause different tools to display different extracted file types.
On compromised web servers, GootLoader-related WordPress implants have been observed embedded in core and theme files and in database-backed options, collecting visitor metadata and relaying commands or content from backend infrastructure. These implants support the SEO-poisoning workflow by redrawing pages, serving lure content, and brokering delivery of malicious archives.
GootLoader primarily targets Windows users and is notable less as a standalone final payload than as a resilient access platform that bridges initial compromise to broader intrusion activity. Victims have included organizations and users searching for legal, business, and other document-related content, with campaigns observed across North America, Europe, South Korea, Australia, and other regions.
C2 tracking
Derp observations, rolling seven-day window
Samples
Reported operators
While the Lorem Ipsum and Gootloader chains are technically distinct, the shared reliance on compromised WordPress infrastructure suggests either common access broker sources, shared compromise tooling, or operator-level coordination between the two pipelines.
While the Lorem Ipsum and Gootloader chains are technically distinct, the shared reliance on compromised WordPress infrastructure suggests either common access broker sources, shared compromise tooling, or operator-level coordination between the two pipelines.
Rhysida actors, operating under the Vanilla Tempest cluster, have used Gootloader-based access that hands off to Supper before ransomware is deployed.
During the attack, Vanilla Tempest gained network access through the Storm-0494 threat actor, who infected the victim's systems with the Gootloader malware downloader.
GootLoader, a JavaScript-based malware loader, returned with new obfuscation techniques. It uses custom WOFF2 fonts and exploits WordPress comment sections to deliver malicious payloads.
GootLoader, a JavaScript-based malware loader, returned with new obfuscation techniques. It uses custom WOFF2 fonts and exploits WordPress comment sections to deliver malicious payloads.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.