Hive0127, also known as UNC2565, is a cybercriminal threat actor associated with the distribution of GootLoader, a JavaScript-based malware loader that provides initial access for subsequent intrusions and ransomware operations. Its campaigns primarily use SEO poisoning to direct users searching for documents, including legal templates, to compromised websites hosting malicious archives. Campaigns have also used Google Ads and compromised WordPress sites to deliver payloads. Hive0127's delivery techniques include abusing WordPress comment endpoints to serve XOR-encrypted ZIP archives with per-file keys and using custom WOFF2 fonts with glyph substitution to disguise filenames displayed in browsers. Malicious archives exploit differences between extraction tools, appearing benign to automated analysis while yielding executable JavaScript through Windows File Explorer. GootLoader has used scheduled tasks for persistence and later shifted to the Windows Startup folder, while continuing to abuse Windows short filenames for detection evasion. GootLoader infections facilitate access handoffs to follow-on operators, including Vanilla Tempest. Associated intrusion chains have deployed the Supper backdoor and remote-access software before ransomware deployment, including INC. In October 2025, two observed GootLoader infections progressed to hands-on-keyboard activity and domain controller compromise within 17 hours. These downstream activities demonstrate the operational impact of GootLoader-delivered access but do not establish that Hive0127 itself operates the resulting ransomware.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An initial-access activity cluster associated with Gootloader infections. The reference describes its handoff of compromised access to Vanilla Tempest for subsequent backdoor installation and ransomware deployment.
Activity cluster associated with GootLoader infections delivered via SEO poisoning and compromised WordPress infrastructure; recent cases led to hands-on-keyboard intrusions including lateral movement and domain controller compromise.
Associated with renewed GootLoader activity using new obfuscation techniques, including custom WOFF2 fonts with glyph substitution and WordPress comment endpoints to deliver XOR-encrypted ZIP payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.