home.social

#gootloader — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #gootloader, aggregated by home.social.

fetched live
  1. Gootloader - ein JavaScript‑basierter Malware‑Loader - ist mit neuen "Tricks" wieder zurück, berichtet gootloader.wordpress.com/2025/
    Gootloader werde über kompromittierte oder vom Angreifer kontrollierte Websites verbreitet verleite Benutzer:innen dazu, Malware - gern als Ransomware - verseuchte Dokumente herunterzuladen.

    Die Websites werden in Suchmaschinen entweder über Anzeigen oder über Suchmaschinenoptimierung (SEO‑Poisoning) beworben, wodurch sie für bestimmte Schlüsselwörter wie „rechtliche Dokumente“ und „Verträge“ höher im Ergebnis erscheinen.
    Also: Vorsicht mit Websites, die rechtliche Dokumente zum Download anbieten.

    #infosec #infosecnews #gootloader #malware #Ransomware #BeDiS

  2. I've been waiting for this writeup for a long time. Great dive on #Gootloader: news.sophos.com/en-us/2025/01/

    Of particular note is the 24-hour timeout for any IP that receives a Gootloader download prompt, frustrating research attempts. But the whole research process here is excellent.

  3. I've been waiting for this writeup for a long time. Great dive on #Gootloader: news.sophos.com/en-us/2025/01/

    Of particular note is the 24-hour timeout for any IP that receives a Gootloader download prompt, frustrating research attempts. But the whole research process here is excellent.

  4. We don't want to tell the entire story here, but the bottom line is this: #Gootloader is and remains one of the most convoluted #malware attack methods we've seen. Its social engineering ruse and the way it shapes itself to your desires still convince people to click its bad links.

    Gootloader has been playing the long game, and winning, below most people's radar, for years. It shows no sign of slowing down or changing its methods. After all, it's a working formula.

    /end

    news.sophos.com/en-us/2025/01/

  5. We don't want to tell the entire story here, but the bottom line is this: #Gootloader is and remains one of the most convoluted #malware attack methods we've seen. Its social engineering ruse and the way it shapes itself to your desires still convince people to click its bad links.

    Gootloader has been playing the long game, and winning, below most people's radar, for years. It shows no sign of slowing down or changing its methods. After all, it's a working formula.

    /end

    news.sophos.com/en-us/2025/01/

  6. CW: re: Long thread

    When a site visitor follows one of the maliciously SEOed search terms (only on the first visit), the WordPress page redraws the #Gootloader content over the WordPress stuff that should appear there.

    It retrieves the redrawn content by connecting to what we've called "the mothership" - a server hosted elsewhere that, in moments, delivers a bogus webpage with a dynamically-generated fictional Q&A.

    It is a very convincing social engineering trick.

    7/

  7. CW: re: Long thread

    When a site visitor follows one of the maliciously SEOed search terms (only on the first visit), the WordPress page redraws the #Gootloader content over the WordPress stuff that should appear there.

    It retrieves the redrawn content by connecting to what we've called "the mothership" - a server hosted elsewhere that, in moments, delivers a bogus webpage with a dynamically-generated fictional Q&A.

    It is a very convincing social engineering trick.

    7/

  8. CW: re: Long thread

    It also turns out that #Gootloader's operators have injected remote shells into a very common WordPress page that exists in most self-hosted WordPress installations. The HelloDolly.php file serves no purpose other than to insert random quotes from the eponymous song into backend admin pages.

    It exists as a prototype of the ways WordPress can insert dynamically-generated content into a page, but it has been modified on some of the #Gootloader sites to contain a backdoor that gives them a backup method to execute commands on the server hosting the WordPress instance.

    6/

  9. CW: re: Long thread

    It also turns out that #Gootloader's operators have injected remote shells into a very common WordPress page that exists in most self-hosted WordPress installations. The HelloDolly.php file serves no purpose other than to insert random quotes from the eponymous song into backend admin pages.

    It exists as a prototype of the ways WordPress can insert dynamically-generated content into a page, but it has been modified on some of the #Gootloader sites to contain a backdoor that gives them a backup method to execute commands on the server hosting the WordPress instance.

    6/

  10. CW: re: Long thread

    This research uncovered the fact that #Gootloader's operators dynamically add those IP address ranges to a block list stored inside the WordPress database, itself.

    5/

  11. CW: re: Long thread

    This research uncovered the fact that #Gootloader's operators dynamically add those IP address ranges to a block list stored inside the WordPress database, itself.

    5/

  12. CW: re: Long thread

    One way the #Gootloader operators conceal themselves in plain sight from the website's owner is by carefully controlling exactly how victims end up in their trap.

    You can't get there by visiting the site URL; The request must contain a Referer header that shows you clicked a Google result.

    And even if you stumble into their trap, if you try to do it a second time, #Gootloader will lock out not just your IP address, but the entire IP address range where you connect from, just for good measure.

    4/

  13. CW: re: Long thread

    One way the #Gootloader operators conceal themselves in plain sight from the website's owner is by carefully controlling exactly how victims end up in their trap.

    You can't get there by visiting the site URL; The request must contain a Referer header that shows you clicked a Google result.

    And even if you stumble into their trap, if you try to do it a second time, #Gootloader will lock out not just your IP address, but the entire IP address range where you connect from, just for good measure.

    4/

  14. CW: re: Long thread

    Nobody knows exactly how the #Gootloader operators are finding and taking control over personal and business websites that use WordPress, but it's likely due to an earlier compromise of the site's administrator credentials, through #malware or #phishing. Stolen credentials for WordPress sites are a dime a dozen on the criminal underground.

    The insidious nature of Gootloader means even the site's owners, who still have working admin passwords, cannot readily determine that the site is being misused for evil.

    3/

  15. CW: re: Long thread

    Nobody knows exactly how the #Gootloader operators are finding and taking control over personal and business websites that use WordPress, but it's likely due to an earlier compromise of the site's administrator credentials, through #malware or #phishing. Stolen credentials for WordPress sites are a dime a dozen on the criminal underground.

    The insidious nature of Gootloader means even the site's owners, who still have working admin passwords, cannot readily determine that the site is being misused for evil.

    3/

  16. Hi everyone, it's @threatresearch driving the X-Ops social media today to let you know about a story we just published, written by my colleague Gabor Szappanos.

    Szapi has done significant research in the past into a #malware family called #Gootloader that (for years, now) uses malicious #SEO techniques to promote compromised websites into Google search results.

    This research finally cracks wide open the mystery of how they manage to do that so effectively. It's a long read, but well worth the deep dive.

    news.sophos.com/en-us/2025/01/

    1/

  17. Hi everyone, it's @threatresearch driving the X-Ops social media today to let you know about a story we just published, written by my colleague Gabor Szappanos.

    Szapi has done significant research in the past into a #malware family called #Gootloader that (for years, now) uses malicious #SEO techniques to promote compromised websites into Google search results.

    This research finally cracks wide open the mystery of how they manage to do that so effectively. It's a long read, but well worth the deep dive.

    news.sophos.com/en-us/2025/01/

    1/

  18. "Gootloader’s Pivot from SEO Poisoning: PDF Converters Become the New Infection Vector"👀
    ⬇️
    "Visiting this WordPress site (surprise!), I found a form for uploading a PDF to convert it to a .DOCX file inside a .zip. But after passing certain checks—being from an English-speaking country and not having visited in the past 24 hours on the same class C subnet—users instead receive a .JS file inside the .zip rather than a genuine .DOCX."
    👇
    gootloader.wordpress.com/2024/

    #gootloader #CyberVeille #PDFConverter #malware

  19. CapLoader wasn’t designed as an alternative to a traditional NIDS, but the Alerts tab often gives a VERY good overview of the malicious traffic. Here’s a screenshot of CapLoader’s alerts for some recent PCAP files from malware-traffic-analysis.net.

    #Lumma #GootLoader #AgentTesla #RURAT #Remcos #RedLine #BackConnect

  20. CapLoader wasn’t designed as an alternative to a traditional NIDS, but the Alerts tab often gives a VERY good overview of the malicious traffic. Here’s a screenshot of CapLoader’s alerts for some recent PCAP files from malware-traffic-analysis.net.

    #Lumma #GootLoader #AgentTesla #RURAT #Remcos #RedLine #BackConnect

  21. Happy Friday everyone!

    The Cybereason Security Services Team share technical details on an attack that involved the #GootLoader malware. Initial infection (TA0001 - Initial Access) was gained through Search Engine Optimization (SEO) poisoning, when adversaries abuse the capabilities of SEO to direct victims to malicious infrastructure, to deliver the malware (T1608.006). Notable living-off-the-land binaries involved in the attack are WScript, CScript, Powershell, and a Scheduled Task. The scheduled task is pretty interesting because the name of it consists of random words from the English language and are hard coded in the payload, in this example, the task name is "Sustainable Drainage", which may or may not stick out like a sore thumb in any/most environments. As usual, I am leaving out a lot of details that can help you, but that's because I want you to go read it yourself! Its a great read!

    Threat Hunting Tip:
    Creating scheduled tasks (T1053.005 - Scheduled Task/Job: Scheduled Task) for Persistence (TA0007) is another common technique among adversaries. There are also many different aspects to consider when it comes to a scheduled task: the schedule for which it will execute (is it every 5 minutes, hour, or just on logon), what level the task will run (User, Highest, etc) and the location of the file that it is referencing. Looking at all of these aspects and comparing to what already exists in your environment would be a good place to start! Enjoy and Happy Hunting!

    I am Goot (Loader)
    cybereason.com/blog/i-am-goot-

    Intel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #gethunting