GootLoader is a multi-stage, JavaScript-based malware loader targeting Windows systems, first observed in late 2020. Originally used to deliver GootKit, it evolved into an initial-access and payload-delivery platform supporting banking malware, post-exploitation frameworks, backdoors, and ransomware infection chains. Associated operators are tracked as Hive0127 and Storm-0494.
Distribution primarily relies on SEO poisoning and compromised websites, including WordPress sites. Search results lead victims to fabricated forums or document-download pages tailored to their queries, frequently using legal, employment, and agreement-related lures. Victims download ZIP archives and execute malicious JavaScript. Delivery infrastructure has used search-referrer checks, first-visit filtering, and geographic restrictions to selectively expose malicious pages while presenting benign content to other visitors.
The infection chain uses layered JavaScript obfuscation, PowerShell, registry-resident payload staging, and .NET components to retrieve and execute subsequent stages in memory. GootLoader can check Active Directory domain membership and collect host information before communicating with command-and-control infrastructure. Observed persistence mechanisms include scheduled tasks and registry autorun entries. Process hollowing and reflective loading conceal payload execution within legitimate processes. Activity resurfacing in October 2025 introduced modified ZIP extraction methods intended to conceal malware.
Delivered payloads include GootKit, IcedID, Cobalt Strike, and SystemBC. GootLoader infections have preceded REvil and LockBit ransomware deployment; in September 2024, access was handed to Vanilla Tempest before Supper backdoor and INC ransomware deployment. Campaigns have affected enterprise and government environments across multiple regions and sectors, including legal services, finance, automotive, pharmaceutical, energy, and military organizations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The GootLoader report's MITRE CONTEXT section lists CVE-2021-1675 under "Exploitation Vulnerabilities."
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Microsoft observed Gootloader handing off access to Vanilla Tempest to load the Supper backdoor before deploying INC ransomware in September 2024.
Microsoft observed Gootloader handing off access to Vanilla Tempest to load the Supper backdoor before deploying INC ransomware in September 2024.
Microsoft observed Gootloader handing off access to Vanilla Tempest to load the Supper backdoor before deploying INC ransomware in September 2024.
During the month of December 2022, the Cybereason Incident Response (IR) team investigated an incident which involved new deployment methods of GootLoader... GootLoader targets companies in English-speaking countries... targeted attacks have been more prominent against healthcare and finance organizations.
While the Lorem Ipsum and Gootloader chains are technically distinct, the shared reliance on compromised WordPress infrastructure suggests either common access broker sources, shared compromise tooling, or operator-level coordination between the two pipelines.
While the Lorem Ipsum and Gootloader chains are technically distinct, the shared reliance on compromised WordPress infrastructure suggests either common access broker sources, shared compromise tooling, or operator-level coordination between the two pipelines.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
These attacks come directly on the heels of an extensive and well-planned Drive-By-Download Campaign ... launched in late December. This malicious campaign’s sole purpose is to infect business professionals’ computer systems with the Sodin ransomware, the Gootkit banking trojan or the Cobalt Strike intrusion tool.
GootLoader has been observed to create scheduled tasks and registry keys for persistence.
A script attempts to reach out and connect to Command and Control domains utilizing obfuscated PowerShell scripts.
271 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
124 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a loader / initial access malware associated with access brokerage used to help obtain initial access for INC Ransom operations.
Malware/loader used in SEO-poisoning campaigns via compromised WordPress sites and fake forum pages offering legal or business document templates; used to gain initial footholds that are then sold to ransomware operators.
Gootloader2
A loader used for initial access in Rhysida intrusions, handing off to Supper before ransomware deployment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.