GootKit
Aliases: Waldek, Xswkit, talalpek
- First seen
- 2014-01-01 00:00:00
- Malware type
- trojan, loader, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:36:56
- Profile updated
- 2026-07-07 13:44:00
Targeted industries: financial-services
Targeted regions: country_code:us country_code:de country_code:uk
Context
Gootkit is a banking trojan consisting of an x86 loader and a payload embedding nodejs as well as a set of js scripts. The loader downloads the payload, stores it in registry and injects it in a copy of the loader process. The loader also contains two encrypted DLLs intended to be injected into each browser process launched in order to place the payload in man in the browser and allow it to apply the webinjects received from the command and control server on HTTPx exchanges. This allows Gootkit to intercept HTTPx requests and responses, steal their content or modify it according to the webinjects.
Detection coverage
- 3 YARA rules
Detection rules
- ARKBIRD_SOLG_Loa_JS_Gootkit_Nov_2020_1 (yara-rule)
- CAPE_Gootkit (yara-rule)
- MALPEDIA_Win_Gootkit_Auto (yara-rule)
Reports & references
- blog.malwarebytes.com — German Users Targeted With Gootkit Banker Or Revil Ransomware (report)
- blogs.blackberry.com — Revil Under The Microscope (report)
- cronup.com — De Ataque Con Malware A Incidente De Ransomware (report)
- Trend Micro — Gootkit Loaders Updated Tactics And Fileless Delivery Of Cobalt Strike (report)
- Trend Micro — Ssl Tls Technical Brief (report)
- resource.redcanary.com — 2022 Threatdetectionreport Redcanary (report)
- Trend Micro — Gootkit Loader Actively Targets The Australian Healthcare Indust (report)
- thedfirreport.com — Seo Poisoning A Gootloader Story (report)
- Kaspersky — 57865 (report)
- dissectingmalwa.re — Nicht So Goot Breaking Down Gootkit And Jasper Ftcode (report)
- blogs.blackberry.com — Threat Spotlight Gootkit Banking Trojan (report)
- youtube.com — Watch (report)
- Palo Alto Unit 42 — Wireshark Tutorial Emotet Infection (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Gootkit (report)
- blog.cert.societegenerale.com — Analyzing Gootkits Persistence Mechanism (report)
- Trend Micro — Fake Judicial Spam Leads To Backdoor With Fake Certificate Authority (report)
- us-cert.gov — Ta16 336A (report)
- sentinelone.com — Gootkit Banking Trojan Deep Dive Anti Analysis Features (report)
- Kaspersky — Inside The Gootkit Cc Server (report)
- youtube.com — Watch (report)
- s21sec.com — Reverse Engineering Gootkit (report)
- forums.juniper.net — 319055 (report)
- 5556002.fs1.hubspotusercontent-na1.net — Public Gootloader%20 %20Foreign%20Intelligence%20Service (report)
- certego.net — Malware Tales Gootkit (report)
- github.com — Gootkit Malware.Md (report)