Gootloader

MITRE ATT&CK: S1138 View on attack.mitre.org

Aliases: SLOWPOUR, Gootloader

First seen
2020-01-01 00:00:00
Malware type
loader
Family
Malware family
Operating systems
windows
Related IoCs
822 (491 malicious)
Last IoC activity
2026-09-02 01:54:18
Profile updated
2026-07-07 13:07:51

Targeted industries: financial-services defense-and-aerospace energy-and-utilities healthcare-and-pharmaceutical government-and-public-sector manufacturing

Context

Gootloader is a Javascript-based infection framework that has been used since at least 2020 as a delivery method for the Gootkit banking trojan, Cobalt Strike, REvil, and others. Gootloader operates on an "Initial Access as a Service" model and has leveraged SEO Poisoning to provide access to entities in multiple sectors worldwide including financial, military, automotive, pharmaceutical, and energy.

Recent IoC activity

492 malicious indicators in Maltiverse are attributed to Gootloader (S1138). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname firmenakademie.com 2026-09-03 2
hostname my-game.biz 2026-09-03 1
hostname youngtechcoorp.com 2026-09-03 1
hostname www.imkerei.email 2026-09-03 1
hostname www.dancesportacademy.nl 2026-09-03 1
hostname www.dgccollectors.com 2026-09-03 1
hostname www.doctorsacademy.org 2026-09-03 1
URL https://vancleefinc.com/blog.php 2026-09-02 2
hostname www.adunion.se 2026-09-02 1
hostname www.altenabrass.nl 2026-09-02 1
hostname www.arton-bv.nl 2026-09-02 1
hostname offshorereview.com 2026-09-02 1
hostname www.fahrschule-br.de 2026-09-02 1
hostname www.criticalcare-neurotrauma.ca 2026-09-02 1
hostname pasta-mania.it 2026-09-02 1
hostname www.walkingholidays.co.za 2026-09-02 1
URL https://bvp.ch/transfer-agreement-concept/ 2026-09-02 1
hostname www.welchwrite.com 2026-09-02 1
hostname yestoday-piano-bar.fr 2026-09-02 1
hostname www.essistme.com 2026-09-02 1

Detection coverage

  • 471 Sigma rules

Malware & tools used

  • System Location Discovery (attack-pattern)
  • Domains (attack-pattern)
  • Domain Groups (attack-pattern)
  • Web Services (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • PowerShell (attack-pattern)
  • Time Based Checks (attack-pattern)
  • System Language Discovery (attack-pattern)
  • Malicious Link (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • JavaScript (attack-pattern)
  • Portable Executable Injection (attack-pattern)
  • Process Hollowing (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)

Reports & references

  • Mandiant — Tracking Evolution Gootloader Operations (report)
  • socradar.io — New Gootloader Variant Gootbot Changes The Game In Malware Tactics (report)
  • securityintelligence.com — Gootbot Gootloaders New Approach To Post Exploitation (report)
  • services.google.com — M Trends 2025 En (report)
  • x.com — 1836456406276342215 (report)
  • intrinsec.com — Tlp Clear Prospero Proton66 Uncovering The Links Between Bulletproof Networks (report)
  • intrinsec.com — Prospero Proton66 Tracing Uncovering The Links Between Bulletproof Networks (report)
  • Mandiant — 1 (report)
  • krebsonsecurity.com — Notorious Malware Spam Host Prospero Moves To Kaspersky Lab (report)
  • malpedia.caad.fkie.fraunhofer.de — Js.Gootloader (report)
  • reliaquest.com — Gootloader Infection Credential Access (report)
  • googlecloudcommunity.com — 823766 (report)
  • Trend Micro — Gootkit Loader Actively Targets The Australian Healthcare Indust (report)
  • expel.com — Gootloaders Malformed Zip (report)
  • labs.sentinelone.com — Gootloader Initial Access As A Service Platform Expands Its Search For High Value Targets (report)
  • blog.nviso.eu — Analysis Of A Trojanized Jquery Script Gootloader Unleashed (report)
  • redcanary.com — Gootloader (report)
  • thedfirreport.com — Seo Poisoning To Domain Control The Gootloader Saga Continues (report)
  • dinohacks.blogspot.com — Loading Gootloader (report)
  • blogs.blackberry.com — Gootloader From Seo Poisoning To Multi Stage Downloader (report)
  • gootloader.wordpress.com — My Game Retired Latest Changes To Gootloader (report)
  • esentire.com — Gootloader Unloaded (report)
  • github.com — Gootloader (report)
  • huntress.com — Gootloader Threat Detection Woff2 Obfuscation (report)
  • trustwave.com — Gootloader Why Your Legal Document Search May End In Misery (report)

External references