logo

THREAT ALERT: GootLoader - Large payload leading to compromise (BLOG)

ID: 4f7fd493-c694-4d3c-8c50-e18c3b80af8d

STIX ID: report--4f7fd493-c694-4d3c-8c50-e18c3b80af8d

Threat Score

85/100

Uploaded: 2026-08-21

Published Date: 2026-02-13

Last Modified Date: 2026-02-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cybereason Threat Alert describes the GootLoader SEO poisoning campaign that leverages compromised WordPress sites, watering-hole delivery, and large obfuscated JavaScript payloads to install malware, deploy post-exploitation frameworks such as Cobalt Strike and SystemBC, establish persistence via scheduled tasks, and conduct data-stage exfiltration and remote control through C2 infrastructure, with extensive indicators of compromise and recommended mitigations.