Gootkit is a modular, multi-stage Windows banking trojan first discovered in 2014. It combines banking fraud functionality with extensive information-stealing and surveillance capabilities. Victims have predominantly been located in European Union countries, including Germany and Italy, with campaigns targeting banking customers and business users.
Its architecture includes a C++ loader and a JavaScript main body executed through a bundled Node.js runtime. Gootkit steals authentication credentials, browser data and cookies, captures keystrokes and screenshots, and collects form submissions and email-related information. It transmits collected data to command-and-control servers and processes commands through a modular framework. Browser-targeted DLL injection enables man-in-the-browser attacks, JavaScript web injection, and modification or redirection of web traffic. Injected code can patch certificate-validation functions to accept self-signed certificates.
Gootkit uses multi-stage packing, encrypted strings, anti-debugging checks, and extensive virtual-machine and sandbox detection. Some environmental checks cause execution to stall indefinitely when analysis conditions are detected. It establishes persistence through Windows services or abuse of pending Group Policy settings, depending on its execution context. Gootkit-associated activity has also involved abuse of Microsoft Defender Antivirus exclusions.
Distribution has included malicious spam, exploit kits such as RIG and Spelevo, and compromised websites that entice visitors to download malicious files. GootLoader, a distinct delivery framework originally developed to deliver Gootkit, uses search-engine optimization poisoning and fake forum-style download lures on compromised websites. Gootkit has also been delivered by Emotet and JasperLoader, and has appeared among payloads historically distributed by the financially motivated actor Storm-0324. Gootkit infections have been associated with subsequent REvil ransomware activity; Gootkit itself is not ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Prior to this threat, Storm-0324 had the following range of payload distribution: ... Gootkit.”
We have observed final payloads including Ramnit, Gootkit, DarkVNC, Ursnif, and PsiXBot.
Delivered malware included ZLoader (a.k.a. Terdot), Gootkit, Ursnif, Corebot, Panda Banker, Atmos, Mazar Bot, and Red Alert Android malware.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
GootLoader is an initial access malware... It is delivered through drive-by social engineering attacks.
Initially it was distributed via spam and exploits kits such as Spelevo and RIG.
The emails include ZIP attachments, pre-downloaded from the attacker’s server, containing a decoy PDF file and a malicious VBS file.
The emails are crafted in the targeted country’s language and are often personalized to include recipients’ names and addresses in various parts of the email such as email body and subject. TA554 frequently uses package delivery or order notification lures; the emails contain URLs linking to zipped LNK files or zipped documents.
The Gootkit Banking Trojan was discovered back in 2014, and utilizes the Node.JS library to perform a range of malicious tasks.
Executing the VBS file leads to downloading further malware using a PowerShell command.
the loader tries to find registry keys with the following format: HKCU\Software\AppDataLow\<pr_string>_<i> ... Each key contains a maximum chunk of 512,000 bytes (500KB) of encrypted data. | So Gootkit creates an .inf file in the same directory as the sample and writes the following values to the Software\Microsoft\IEAK\GroupPolicy\PendingGPOs registry key
If the sample is running under another account, it creates a service with a random name chosen from %SystemRoot%, copies itself into the %SystemRoot% folder with the chosen name and deletes itself from the disk.
iterates over the running processes and tries to inject the decrypted DLLs into the process memory of the designated process using the NtCreateSection/NtMapViewOfSection API.
The loader is composed of three highly obfuscated layers that contain encoded URLs.
iterates over the running processes and tries to inject the decrypted DLLs into the process memory of the designated process using the NtCreateSection/NtMapViewOfSection API.
Note that each “while” loop is performing string decryption on the sequences of bytes shown in the variables above the loop. When following the execution in a debugger, the strings are decrypted, and some meaningful indicators of VM checks are visible.
the Gootkit loader employs lots of different methods to detect virtual environments or debuggers. If any of the virtual machine checks succeed, the loader enters an infinite loop.
The rest of the checks include: Compare user name to "CurrentUser"/"Sandbox" Compare computer name to "SANDBOX"/"7SILVIA" HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion" compare with AMI, VirtualBox, BOCHS, INTEL 640000, 55274-640-2673064-23950, and other serials
the loader tries to find registry keys with the following format: HKCU\Software\AppDataLow\<pr_string>_<i> ... Each key contains a maximum chunk of 512,000 bytes (500KB) of encrypted data. | So Gootkit creates an .inf file in the same directory as the sample and writes the following values to the Software\Microsoft\IEAK\GroupPolicy\PendingGPOs registry key
Continuing on, Gootkit will query HARDWARE\DESCRIPTION\System\SystemBiosVersion and compare the value to; AMI, BOCHS, VBOX, QEMU... Yet another registry query is performed, this time with the key HARDWARE\Description\System\VideoBiosVersion.
the Gootkit loader employs lots of different methods to detect virtual environments or debuggers. If any of the virtual machine checks succeed, the loader enters an infinite loop.
The rest of the checks include: Compare user name to "CurrentUser"/"Sandbox" Compare computer name to "SANDBOX"/"7SILVIA" HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\SystemBiosVersion" compare with AMI, VirtualBox, BOCHS, INTEL 640000, 55274-640-2673064-23950, and other serials
Gootkit is capable of stealing data from the browser, performing man-in-the-browser attacks, keylogging, taking screenshots
Indicators of Compromise ... jonathanbartz[.]com Command and Control
Gootloader, which attempts to retrieve the final payload, whether it be ransomware, a banking trojan or intrusion tool/credential stealer.
Recently, we came across web malware that – instead of injecting an iframe pointing to a fixed existing address – generates a pseudo-random domain name, depending on the current date. This approach is not new and is widely used by botnets in C&C domain name generation.
112 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
61 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a historical example connected to abuse of Microsoft Defender Antivirus exclusions.
Listed as a payload historically distributed by Storm-0324. No technical details or current-campaign involvement are provided.
Gootkit is a banking trojan first reported in 2014 that uses Node.js components and supports persistence, C2-based loader updates, browser DLL injection, credential theft, web injections, video recording, and remote VNC-style access. In this sample it establishes persistence via either a created Windows service or an IEAK PendingGPO INF-based mechanism, disables Internet Explorer Protected Mode across zones, scans for browsers, and injects x86/x64 DLLs into targeted browser processes.
The State of SSL/TLS Certificate Usage in Malware C&C Communications AdWind ostap AsyncRAT BazarBackdoor BitRAT Buer Chthonic CloudEyE Cobalt Strike DCRat Dridex FindPOS GootKit Gozi IcedID ISFB Nanocore RAT Orcus RAT PandaBanker Qadars QakBot Quasar RAT Rockloader ServHelper Shifu SManager TorrentLocker TrickBot Vawtrak Zeus Zloader
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.