By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: GootLoader Malware Still Active, Deploys New Versions for Enhanced Attacks
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > GootLoader Malware Still Active, Deploys New Versions for Enhanced Attacks
Tech News

GootLoader Malware Still Active, Deploys New Versions for Enhanced Attacks

By Viral Trending Content 3 Min Read
Share
SHARE

Jul 05, 2024NewsroomSEO Poisoning / Cyber Attack,

GootLoader Malware

The malware known as GootLoader continues to be in active use by threat actors looking to deliver additional payloads to compromised hosts.

“Updates to the GootLoader payload have resulted in several versions of GootLoader, with GootLoader 3 currently in active use,” cybersecurity firm Cybereason said in an analysis published last week.

“While some of the particulars of GootLoader payloads have changed over time, infection strategies and overall functionality remain similar to the malware’s resurgence in 2020.”

Cybersecurity

GootLoader, a malware loader part of the Gootkit banking trojan, is linked to a threat actor named Hive0127 (aka UNC2565). It abuses JavaScript to download post-exploitation tools and is distributed via search engine optimization (SEO) poisoning tactics.

It typically serves as a conduit for delivering various payloads such as Cobalt Strike, Gootkit, IcedID, Kronos, REvil, and SystemBC.

GootLoader Malware

In recent months, the threat actors behind GootLoader have also unleashed their own command-and-control (C2) and lateral movement tool dubbed GootBot, indicating that the “group is expanding their market to gain a wider audience for their financial gains.”

Attack chains involve compromising websites to host the GootLoader JavaScript payload by passing it off as legal documents and agreements, which, when launched, sets up persistence using a scheduled task and executes additional JavaScript to kick-start a PowerShell script for collecting system information and awaiting further instructions.

Cybersecurity

“Sites that host these archive files leverage Search Engine Optimization (SEO) poisoning techniques to lure in victims that are searching for business-related files such as contract templates or legal documents,” security researchers Ralph Villanueva, Kotaro Ogino, and Gal Romano said.

The attacks are also notable for making use of source code encoding, control flow obfuscation, and payload size inflation in order to resist analysis and detection. Another technique entails embedding the malware in legitimate JavaScript library files like jQuery, Lodash, Maplace.js, and tui-chart.

“GootLoader has received several updates during its life cycle, including changes to evasion and execution functionalities,” the researchers concluded.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Old Oil and Gas Wells Could Find Second Life Producing Clean Energy

NIST to stop rating non-priority flaws due to volume increase

Pharmaceutical Takeda to cut 4,500 from global workforce

What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface

Google Just Launched its MacBook Neo Trump Card

TAGGED: Cyber Attack, Cyber Security, Cybereason, Cybersecurity, data protection, Internet, Malware, network security, Ransomware, SEO poisoning, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article Metal Gear Rising: Revengeance is Now Available on GOG
Next Article Solana price prediction ahead of Poodlana (POODL) launch
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Diablo 4 Bug Fix Accidentally Makes Players Basically Immortal Instead: ‘Yep This Broke The Game”
Gaming News
Will airfares be easier on our wallets this summer? Some carriers are cutting prices
Travel
Multibaggers, mirages and market math
Business
Spot Bitcoin ETFs bleed $1B in a week, snapping six-week inflow run
Crypto
Old Oil and Gas Wells Could Find Second Life Producing Clean Energy
Tech News
NIST to stop rating non-priority flaws due to volume increase
Tech News
If someone starts investing now with £18 a day, how much might they have by Christmas?
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Diablo 4 Bug Fix Accidentally Makes Players Basically Immortal Instead: ‘Yep This Broke The Game”

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Diablo 4 Bug Fix Accidentally Makes Players Basically Immortal Instead: ‘Yep This Broke The Game”
May 16, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?