TF-MAL-js.gootloader
📛 Threat Title
Malware family: GootLoader
Description
ThreatFox malware family `js.gootloader`. Printable name: GootLoader. Aliases: SLOWPOUR.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.gootloader
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.gootloader
IOC database
- Type
- domain
- Value
js.gootloader- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.gootloader
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.gootloader
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family . The page below gives you an overview on malware samples that MalwareBazaar has identified as GootLoader .
-
web:cloud.google.com
Since January 2021, Mandiant Managed Defense has consistently responded to GOOTLOADER infections. Threat actors cast a widespread net when spreading GOOTLOADER and impact a wide range of industry verticals and geographic regions. We currently only attribute GOOTLOADER malware and infrastructure to a group we track as UNC2565, and we believe it to be exclusive to this group.
-
web:cyberpress.org
Gootloader malware continues to evade detection, bypassing most security tools while maintaining a low detection rate.
-
web:cybersecsentinel.com
Threat Group - UNC2565 (also tracked as Storm-0494) Threat Type - Malware Loader and Initial Access Platform Exploited Vulnerabilities - No specific CVE confirmed. Campaign relies on SEO poisoning, compromised WordPress sites, archive format inconsistencies, Windows Script Host execution, and legacy filename behaviour. Malware Used - GootLoader , GootBot, secondary payloads such as ...
-
web:dailysecurityreview.com
The Gootloader malware gang has resurfaced after months of inactivity, reviving its signature SEO poisoning attacks. By manipulating search results to distribute malicious downloads through fake forum pages, the group continues to target business users with stealthy, region-specific malware delivery campaigns.
-
web:hivepro.com
Return of Gootloader : Blending Technical Evasion with Operational Discipline Summary Gootloader malware has re-emerged with renewed and aggressive operations starting October 27, 2025, targeting organizations worldwide through sophisticated SEO poisoning and compromised WordPress sites. The latest Gootloader campaigns demonstrate rapid operational efficiency, achieving domain controller ...
-
web:redcanary.com
Gootloader is a pervasive threat affecting enterprise organizations. This blog includes malware analysis and detection opportunities.
-
web:thehackernews.com
The JavaScript (aka JScript) malware loader called GootLoader has been observed using a malformed ZIP archive that's designed to sidestep detection efforts by concatenating anywhere from 500 to 1,000 archives. "The actor creates a malformed archive as an anti-analysis technique," Expel security ...
-
web:www.huntress.com
Overview Gootloader is a sophisticated JavaScript-based malware loader that threat actors commonly use to gain initial access. This malware is typically delivered when users visit compromised websites, with threat actors leveraging SEO poisoning to drive traffic to these sites.
-
web:www.microsoft.com
Gootloader is an initial access malware family that traces its lineage to the Gootkit banking trojan. It now operates as an Initial-Access-as-a-Service (IAaaS) platform for ransomware affiliates. The malware uses a multi-stage JavaScript architecture and only delivers its full payload to Windows devices joined to Active Directory domains.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.