#gootloader — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #gootloader, aggregated by home.social.
-
Gootloader - ein JavaScript‑basierter Malware‑Loader - ist mit neuen "Tricks" wieder zurück, berichtet https://gootloader.wordpress.com/2025/11/05/gootloader-is-back-back-again/
Gootloader werde über kompromittierte oder vom Angreifer kontrollierte Websites verbreitet verleite Benutzer:innen dazu, Malware - gern als Ransomware - verseuchte Dokumente herunterzuladen.Die Websites werden in Suchmaschinen entweder über Anzeigen oder über Suchmaschinenoptimierung (SEO‑Poisoning) beworben, wodurch sie für bestimmte Schlüsselwörter wie „rechtliche Dokumente“ und „Verträge“ höher im Ergebnis erscheinen.
Also: Vorsicht mit Websites, die rechtliche Dokumente zum Download anbieten.#infosec #infosecnews #gootloader #malware #Ransomware #BeDiS
-
Gootloader is back with a vengeance—this time featuring the stealthy GootBot that spreads through networks and ups its SEO poisoning game. With targets from legal to healthcare, are we ready for its next-gen tactics?
#gootloader
#malwaretrends
#cybersecurity2024
#threatintelligence
#infosec
#gootbot
#seoattacks
#healthcaresecurity
#ransomware -
Gootloader’s back—and it’s smarter. The new GootBot variant is evading defenses and targeting industries like healthcare. Are we ready for what’s next?
#gootloader
#malwaretrends
#cybersecurity2024
#threatintelligence
#infosec
#gootbot
#seoattacks
#healthcaresecurity
#ransomware -
Gootloader’s back—and it’s smarter. The new GootBot variant is evading defenses and targeting industries like healthcare. Are we ready for what’s next?
#gootloader
#malwaretrends
#cybersecurity2024
#threatintelligence
#infosec
#gootbot
#seoattacks
#healthcaresecurity
#ransomware -
Gootloader is back with a vengeance—this time featuring the stealthy GootBot that spreads through networks and ups its SEO poisoning game. With targets from legal to healthcare, are we ready for its next-gen tactics?
#gootloader
#malwaretrends
#cybersecurity2024
#threatintelligence
#infosec
#gootbot
#seoattacks
#healthcaresecurity
#ransomware -
Gootloader Malware Resurfaces in Google Ads for Legal Docs – Source: www.darkreading.com https://ciso2ciso.com/gootloader-malware-resurfaces-in-google-ads-for-legal-docs-source-www-darkreading-com/ #rssfeedpostgeneratorecho #DarkReadingSecurity #CyberSecurityNews #DARKReading #Gootloader
-
Gootloader Malware Resurfaces in Google Ads for Legal Docs – Source: www.darkreading.com https://ciso2ciso.com/gootloader-malware-resurfaces-in-google-ads-for-legal-docs-source-www-darkreading-com/ #rssfeedpostgeneratorecho #DarkReadingSecurity #CyberSecurityNews #DARKReading #Gootloader
-
Gootloader Returns: Malware Hidden in Google Ads for Legal Documents
#GootLoader
https://gootloader.wordpress.com/2025/03/31/gootloader-returns-malware-hidden-in-google-ads-for-legal-documents/ -
Notorious Malware, Spam Host “Prospero” Moves to Kaspersky Lab
https://krebsonsecurity.com/2025/02/notorious-malware-spam-host-prospero-moves-to-kaspersky-lab/
#InterisleConsultingGroup #Ne'er-Do-WellNews #ALittleSunshine #TheComingStorm #KasperskyLab #ProsperoOOO #ZachEdwards #Ransomware #GootLoader #Securehost #SilentPush #SocGholish #Intrinsec #AlfaBank #BEARHOST #spamhaus #Kentik
-
Notorious Malware, Spam Host “Prospero” Moves to Kaspersky Lab
https://krebsonsecurity.com/2025/02/notorious-malware-spam-host-prospero-moves-to-kaspersky-lab/
#InterisleConsultingGroup #Ne'er-Do-WellNews #ALittleSunshine #TheComingStorm #KasperskyLab #ProsperoOOO #ZachEdwards #Ransomware #GootLoader #Securehost #SilentPush #SocGholish #Intrinsec #AlfaBank #BEARHOST #spamhaus #Kentik
-
Notorious Malware, Spam Host “Prospero” Moves to Kaspersky Lab https://krebsonsecurity.com/2025/02/notorious-malware-spam-host-prospero-moves-to-kaspersky-lab/ #InterisleConsultingGroup #Ne'er-Do-WellNews #ALittleSunshine #TheComingStorm #KasperskyLab #ProsperoOOO #ZachEdwards #Ransomware #GootLoader #Securehost #SilentPush #SocGholish #Intrinsec #AlfaBank #BEARHOST #spamhaus #Kentik
-
Notorious Malware, Spam Host “Prospero” Moves to Kaspersky Lab https://krebsonsecurity.com/2025/02/notorious-malware-spam-host-prospero-moves-to-kaspersky-lab/ #InterisleConsultingGroup #Ne'er-Do-WellNews #ALittleSunshine #TheComingStorm #KasperskyLab #ProsperoOOO #ZachEdwards #Ransomware #GootLoader #Securehost #SilentPush #SocGholish #Intrinsec #AlfaBank #BEARHOST #spamhaus #Kentik
-
Gootloader inside out – Source: news.sophos.com https://ciso2ciso.com/gootloader-inside-out-source-news-sophos-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #ThreatResearch #nakedsecurity #nakedsecurity #maliciousSEO #Obfuscation #obfuscation #Gootloader #HelloDolly #WordPress #Wordpress #FEATURED #PHPshell #featured #Gootkit #JScript #Malware #YARA #PHP #seo #SEO
-
Gootloader inside out – Source: news.sophos.com https://ciso2ciso.com/gootloader-inside-out-source-news-sophos-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #ThreatResearch #nakedsecurity #nakedsecurity #maliciousSEO #Obfuscation #obfuscation #Gootloader #HelloDolly #WordPress #Wordpress #FEATURED #PHPshell #featured #Gootkit #JScript #Malware #YARA #PHP #seo #SEO
-
I've been waiting for this writeup for a long time. Great dive on #Gootloader: https://news.sophos.com/en-us/2025/01/16/gootloader-inside-out/
Of particular note is the 24-hour timeout for any IP that receives a Gootloader download prompt, frustrating research attempts. But the whole research process here is excellent.
-
I've been waiting for this writeup for a long time. Great dive on #Gootloader: https://news.sophos.com/en-us/2025/01/16/gootloader-inside-out/
Of particular note is the 24-hour timeout for any IP that receives a Gootloader download prompt, frustrating research attempts. But the whole research process here is excellent.
-
We don't want to tell the entire story here, but the bottom line is this: #Gootloader is and remains one of the most convoluted #malware attack methods we've seen. Its social engineering ruse and the way it shapes itself to your desires still convince people to click its bad links.
Gootloader has been playing the long game, and winning, below most people's radar, for years. It shows no sign of slowing down or changing its methods. After all, it's a working formula.
/end
https://news.sophos.com/en-us/2025/01/16/gootloader-inside-out/
-
We don't want to tell the entire story here, but the bottom line is this: #Gootloader is and remains one of the most convoluted #malware attack methods we've seen. Its social engineering ruse and the way it shapes itself to your desires still convince people to click its bad links.
Gootloader has been playing the long game, and winning, below most people's radar, for years. It shows no sign of slowing down or changing its methods. After all, it's a working formula.
/end
https://news.sophos.com/en-us/2025/01/16/gootloader-inside-out/
-
CW: re: Long thread
When a site visitor follows one of the maliciously SEOed search terms (only on the first visit), the WordPress page redraws the #Gootloader content over the WordPress stuff that should appear there.
It retrieves the redrawn content by connecting to what we've called "the mothership" - a server hosted elsewhere that, in moments, delivers a bogus webpage with a dynamically-generated fictional Q&A.
It is a very convincing social engineering trick.
7/
-
CW: re: Long thread
When a site visitor follows one of the maliciously SEOed search terms (only on the first visit), the WordPress page redraws the #Gootloader content over the WordPress stuff that should appear there.
It retrieves the redrawn content by connecting to what we've called "the mothership" - a server hosted elsewhere that, in moments, delivers a bogus webpage with a dynamically-generated fictional Q&A.
It is a very convincing social engineering trick.
7/
-
CW: re: Long thread
It also turns out that #Gootloader's operators have injected remote shells into a very common WordPress page that exists in most self-hosted WordPress installations. The HelloDolly.php file serves no purpose other than to insert random quotes from the eponymous song into backend admin pages.
It exists as a prototype of the ways WordPress can insert dynamically-generated content into a page, but it has been modified on some of the #Gootloader sites to contain a backdoor that gives them a backup method to execute commands on the server hosting the WordPress instance.
6/
-
CW: re: Long thread
It also turns out that #Gootloader's operators have injected remote shells into a very common WordPress page that exists in most self-hosted WordPress installations. The HelloDolly.php file serves no purpose other than to insert random quotes from the eponymous song into backend admin pages.
It exists as a prototype of the ways WordPress can insert dynamically-generated content into a page, but it has been modified on some of the #Gootloader sites to contain a backdoor that gives them a backup method to execute commands on the server hosting the WordPress instance.
6/
-
CW: re: Long thread
This research uncovered the fact that #Gootloader's operators dynamically add those IP address ranges to a block list stored inside the WordPress database, itself.
5/
-
CW: re: Long thread
This research uncovered the fact that #Gootloader's operators dynamically add those IP address ranges to a block list stored inside the WordPress database, itself.
5/
-
CW: re: Long thread
One way the #Gootloader operators conceal themselves in plain sight from the website's owner is by carefully controlling exactly how victims end up in their trap.
You can't get there by visiting the site URL; The request must contain a Referer header that shows you clicked a Google result.
And even if you stumble into their trap, if you try to do it a second time, #Gootloader will lock out not just your IP address, but the entire IP address range where you connect from, just for good measure.
4/
-
CW: re: Long thread
One way the #Gootloader operators conceal themselves in plain sight from the website's owner is by carefully controlling exactly how victims end up in their trap.
You can't get there by visiting the site URL; The request must contain a Referer header that shows you clicked a Google result.
And even if you stumble into their trap, if you try to do it a second time, #Gootloader will lock out not just your IP address, but the entire IP address range where you connect from, just for good measure.
4/
-
CW: re: Long thread
Nobody knows exactly how the #Gootloader operators are finding and taking control over personal and business websites that use WordPress, but it's likely due to an earlier compromise of the site's administrator credentials, through #malware or #phishing. Stolen credentials for WordPress sites are a dime a dozen on the criminal underground.
The insidious nature of Gootloader means even the site's owners, who still have working admin passwords, cannot readily determine that the site is being misused for evil.
3/
-
CW: re: Long thread
Nobody knows exactly how the #Gootloader operators are finding and taking control over personal and business websites that use WordPress, but it's likely due to an earlier compromise of the site's administrator credentials, through #malware or #phishing. Stolen credentials for WordPress sites are a dime a dozen on the criminal underground.
The insidious nature of Gootloader means even the site's owners, who still have working admin passwords, cannot readily determine that the site is being misused for evil.
3/
-
Hi everyone, it's @threatresearch driving the X-Ops social media today to let you know about a story we just published, written by my colleague Gabor Szappanos.
Szapi has done significant research in the past into a #malware family called #Gootloader that (for years, now) uses malicious #SEO techniques to promote compromised websites into Google search results.
This research finally cracks wide open the mystery of how they manage to do that so effectively. It's a long read, but well worth the deep dive.
https://news.sophos.com/en-us/2025/01/16/gootloader-inside-out/
1/
-
Hi everyone, it's @threatresearch driving the X-Ops social media today to let you know about a story we just published, written by my colleague Gabor Szappanos.
Szapi has done significant research in the past into a #malware family called #Gootloader that (for years, now) uses malicious #SEO techniques to promote compromised websites into Google search results.
This research finally cracks wide open the mystery of how they manage to do that so effectively. It's a long read, but well worth the deep dive.
https://news.sophos.com/en-us/2025/01/16/gootloader-inside-out/
1/
-
New GootLoader Campaign Targets Users Searching for Bengal Cat Laws in Australia – Source:thehackernews.com https://ciso2ciso.com/new-gootloader-campaign-targets-users-searching-for-bengal-cat-laws-in-australia-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #Gootloader
-
New GootLoader Campaign Targets Users Searching for Bengal Cat Laws in Australia – Source:thehackernews.com https://ciso2ciso.com/new-gootloader-campaign-targets-users-searching-for-bengal-cat-laws-in-australia-sourcethehackernews-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #TheHackerNews #Gootloader
-
Are You Googling This? You Could Be Walking Into a Cyber Trap https://thecyberexpress.com/seo-poisoning-australia/ #AreBengalCatslegalinAustralia #SEOPoisoningAttacks #TheCyberExpressNews #TheCyberExpress #FirewallDaily #MarketReports #GoogleSearch #SEOpoisoning #MalwareNews #HackerNews #GootLoader #CyberNews #Australia #Sophos
-
Are You Googling This? You Could Be Walking Into a Cyber Trap https://thecyberexpress.com/seo-poisoning-australia/ #AreBengalCatslegalinAustralia #SEOPoisoningAttacks #TheCyberExpressNews #TheCyberExpress #FirewallDaily #MarketReports #GoogleSearch #SEOpoisoning #MalwareNews #HackerNews #GootLoader #CyberNews #Australia #Sophos
-
"Gootloader’s Pivot from SEO Poisoning: PDF Converters Become the New Infection Vector"👀
⬇️
"Visiting this WordPress site (surprise!), I found a form for uploading a PDF to convert it to a .DOCX file inside a .zip. But after passing certain checks—being from an English-speaking country and not having visited in the past 24 hours on the same class C subnet—users instead receive a .JS file inside the .zip rather than a genuine .DOCX."
👇
https://gootloader.wordpress.com/2024/11/07/gootloaders-pivot-from-seo-poisoning-pdf-converters-become-the-new-infection-vector/ -
CapLoader wasn’t designed as an alternative to a traditional NIDS, but the Alerts tab often gives a VERY good overview of the malicious traffic. Here’s a screenshot of CapLoader’s alerts for some recent PCAP files from malware-traffic-analysis.net.
#Lumma #GootLoader #AgentTesla #RURAT #Remcos #RedLine #BackConnect
-
CapLoader wasn’t designed as an alternative to a traditional NIDS, but the Alerts tab often gives a VERY good overview of the malicious traffic. Here’s a screenshot of CapLoader’s alerts for some recent PCAP files from malware-traffic-analysis.net.
#Lumma #GootLoader #AgentTesla #RURAT #Remcos #RedLine #BackConnect
-
GootLoader Malware Evades Detection Through Complicated Loops and Time-Based Delays https://thecyberexpress.com/gootloader-malware-evades-time-based-delays/ #TheCyberExpressNews #GootLoaderMalware #PaltoAltoNetworks #TheCyberExpress #FirewallDaily #GootLoader
-
GootLoader Malware Still Active, Deploys New Versions for Enhanced Attacks
https://thehackernews.com/2024/07/gootloader-malware-delivers-new.html #Cybercrime #Malware #GootLoader -
Happy Friday everyone!
The Cybereason Security Services Team share technical details on an attack that involved the #GootLoader malware. Initial infection (TA0001 - Initial Access) was gained through Search Engine Optimization (SEO) poisoning, when adversaries abuse the capabilities of SEO to direct victims to malicious infrastructure, to deliver the malware (T1608.006). Notable living-off-the-land binaries involved in the attack are WScript, CScript, Powershell, and a Scheduled Task. The scheduled task is pretty interesting because the name of it consists of random words from the English language and are hard coded in the payload, in this example, the task name is "Sustainable Drainage", which may or may not stick out like a sore thumb in any/most environments. As usual, I am leaving out a lot of details that can help you, but that's because I want you to go read it yourself! Its a great read!
Threat Hunting Tip:
Creating scheduled tasks (T1053.005 - Scheduled Task/Job: Scheduled Task) for Persistence (TA0007) is another common technique among adversaries. There are also many different aspects to consider when it comes to a scheduled task: the schedule for which it will execute (is it every 5 minutes, hour, or just on logon), what level the task will run (User, Highest, etc) and the location of the file that it is referencing. Looking at all of these aspects and comparing to what already exists in your environment would be a good place to start! Enjoy and Happy Hunting!I am Goot (Loader)
https://www.cybereason.com/blog/i-am-goot-loaderIntel 471 #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #gethunting
-
Threat walkthrough: #Gootloader
https://www.threatdown.com/blog/gootloader-05-23-2024/ -
Jak GootLoader zamienia Wordpress w zombie SEO ( https://nfsec.pl/security/6427 ) #wordpress #seo #malware #gootloader #twittermigration