Once used exclusively by the cybercriminals behind REVil ransomware and the Gootkit banking trojan, GootLoader and its primary payload have evolved into an initial access as a service platform—with Gootkit providing information stealing capabilities as well as the capability to deploy post-exploitation tools and ransomware.
GootLoader is known for using search engine optimization (SEO) poisoning for its initial access. Victims are often enticed into clicking on malicious adware or links disguised as legitimate marketing, or in this case a legitimate Google search directing the user to a compromised website hosting a malicious payload masquerading as the desired file. If the malware remains undetected on the victim’s machine, it makes way for a second-stage payload known as GootKit, which is a highly evasive info stealer and remote access Trojan (RAT) used to establish a persistent foothold in the victim’s network environment.
Read more…
Source: Sophos
Related:
- ICS Cyberwarfare: The Latest Threat to America’s Power Grid
November 20, 2019
The modern world is dependent on electricity, and the United States is no exception. I remember the notorious blackouts that affected the eastern U.S. and Canada in August 2003. The duration of the mass power outage lasted anywhere between several hours and a week depending on where you were. I was in Hamilton, Canada, and ...
- Mac Backdoor Linked to Lazarus Targets Korean Users
November 20, 2019
Criminal interest in MacOS continues to grow, with malware authors churning out more threats that target users of the popular OS. Case in point: A new variant of a Mac backdoor (detected by Trend Micro as Backdoor.MacOS.NUKESPED.A) attributed to the cybercriminal group Lazarus, which was observed targeting Korean users with a macro-embedded Microsoft Excel spreadsheet. Similarities to an ...
- NSA Publishes Advisory Addressing Encrypted Traffic Inspection TLCRisks
November 19, 2019
The National Security Agency (NSA) published an advisory that addresses the risks behind Transport Layer Security Inspection (TLSI) and provides mitigation measures for weakened security in organizations that use TLSI products. TLSI (aka TLS break and inspect) is the process through which enterprises can inspect encrypted traffic with the help of a dedicated product such as a proxy ...
- Is agriculture at risk from cyber crime?
November 18, 2019
Most media coverage about cyber-crime shares horrendous examples of how individuals or families’ lives have been ruined by ruthless scams. This is no different in the agriculture sector. Cyber crime has become a major industry – and the cyber security industry has grown rapidly to tackle the scale of the problem. The Office of National Statistics estimates ...
- New WhatsApp Bug Could Have Let Hackers Secretly Install Spyware On Your Devices
November 16, 2019
The vulnerability affects both consumers as well as enterprise apps of WhatsApp for all major platforms, including Google Android, Apple iOS, and Microsoft Windows. According to an advisory published by Facebook, which owns WhatsApp, the list of affected app versions are as follows: Android versions before 2.19.274 iOS versions before 2.19.100 Enterprise Client versions before 2.25.3 Windows Phone versions before and ...
- Stealthy Malware Flies Under AV Radar with Advanced Obfuscation
November 15, 2019
Researchers warn hackers are putting a new spin on old injection techniques and successfully end-running endpoint protection. They are tracking a campaign, that kicked off in January, that is still going strong exploiting weaknesses in web browsers. The objective is to hide in the background of infected systems in order to steal user passwords, track ...

