Description
Golroted is a trojan downloader observed in campaigns from 2017 that installs further malware, including cryptocurrency miners and ransomware, onto infected systems. It uses process hollowing to run payloads under legitimate processes and bypasses user account control through registry changes, and it launches its stages through trusted framework executables to blend into normal activity. Its appearance as a delivery component in the DarkGate campaign connected the family to broader mining and ransomware operations.
Stats
- First seen
- March 2022
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Spyware.Golroted |
| ByteCode-MSIL.Trojan.Golroted |
| Script-AutoIt.Trojan.Golroted |
| Win32.Trojan.Golroted |