Tag: GootLoader Malware

GootLoader Malware Still Active, Deploys New Versions for Enhanced Attacks
News

GootLoader Malware Still Active, Deploys New Versions for Enhanced Attacks

Threat actors are still actively using the malware known as GootLoader in an effort to infect more hosts with malware. GootLoader has been released in multiple versions due to changes to its payload; the most recent version, GootLoader 3, is presently in use, according to a study released last week by cybersecurity company Cybereason. The general functioning and infection techniques of GootLoader payloads have not altered since the malware's 2020 revival, despite certain payload details changing over time. GootLoader, a malware loader that is a component of the Gootkit financial trojan, has been associated with Hive0127, also known as UNC2565. It is disseminated by search engine optimization (SEO) poisoning techniques and employs malicious JavaScript read more about GootLoader Ma...
New GootLoader Malware Variant Evades Detection and Spreads Rapidly
News

New GootLoader Malware Variant Evades Detection and Spreads Rapidly

It has been discovered that GootBot, a new GootLoader malware variant, makes it easier for compromised systems to move laterally and avoid detection. According to IBM X-Force experts Golo Mühr and Ole Villadsen, "the GootLoader group's introduction of their own custom bot into the late stages of their attack chain is an attempt to avoid detections when using off-the-shelf tools for C2 such as CobaltStrike or RDP." This new version of the virus is lightweight yet powerful, enabling attackers to quickly propagate over the network and drop more payloads. As its name suggests, GootLoader is a malware that can lure in potential victims by employing search engine optimization (SEO) poisoning techniques read more New GootLoader Malware Variant Evades Detection and Spreads Rapidly. Ge...