THREAT ALERT: GootLoader - Large payload leading to compromise (BLOG)
ID: 4f7fd493-c694-4d3c-8c50-e18c3b80af8d
STIX ID: report--4f7fd493-c694-4d3c-8c50-e18c3b80af8d
Threat Score
85/100
Uploaded: 2026-08-21
Published Date: 2026-02-13
Last Modified Date: 2026-02-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cybereason Threat Alert describes the GootLoader SEO poisoning campaign that leverages compromised WordPress sites, watering-hole delivery, and large obfuscated JavaScript payloads to install malware, deploy post-exploitation frameworks such as Cobalt Strike and SystemBC, establish persistence via scheduled tasks, and conduct data-stage exfiltration and remote control through C2 infrastructure, with extensive indicators of compromise and recommended mitigations.
