Netskope Threat Labs

Gootloader

ATP Sandbox Adv. HeuristicsAVNetskope IPS

GootLoader (a.k.a. Gootkit) is a JavaScript based downloader and dropper that cyberattackers distribute through compromised websites and search engine optimization poisoning to deliver additional malware payloads. Victims searching for business documents and templates land on pages seeded with malicious content, and the site serves malicious scripts only once per victim to frustrate analysis. The operation targets professionals in healthcare, legal, and finance, and it has delivered remote access trojans and ransomware to corporate networks.

First seen
July 2022
Last seen
October 2026
GootLoader

18 techniques across 6 tactics.

TA0042 Resource Development

TA0002 Execution

TA0003 Persistence

  • T1547Boot or Logon Autostart Execution

TA0005 Stealth

TA0007 Discovery

  • T1016System Network Configuration Discovery
  • T1069Permission Groups Discovery
  • T1082System Information Discovery
  • T1614System Location Discovery

TA0011 Command and Control

Alert Name
ByteCode-MSIL.Dropper.GootLoader
Generic.JS.GootLoader.A.003BAF5C
Generic.JS.GootLoader.A.0051A043
Generic.JS.GootLoader.A.007941C8
Generic.JS.GootLoader.A.00F0F3B5
Generic.JS.GootLoader.A.02AAD4D7
Generic.JS.GootLoader.A.02DB06F6
Generic.JS.GootLoader.A.03416FF0
Generic.JS.GootLoader.A.035A57B3
Generic.JS.GootLoader.A.05044435