Netskope Threat Labs

Golroted

ATP Sandbox Adv. Heuristics

Golroted is a trojan downloader observed in campaigns from 2017 that installs further malware, including cryptocurrency miners and ransomware, onto infected systems. It uses process hollowing to run payloads under legitimate processes and bypasses user account control through registry changes, and it launches its stages through trusted framework executables to blend into normal activity. Its appearance as a delivery component in the DarkGate campaign connected the family to broader mining and ransomware operations.

First seen
March 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Spyware.Golroted
ByteCode-MSIL.Trojan.Golroted
Script-AutoIt.Trojan.Golroted
Win32.Trojan.Golroted