Gootloader
· Published 21/12/2025 03:26 · Modified 21/12/2025 07:44
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 03:26
- Modified
- 21/12/2025 07:44
- Updated at
- 21/12/2025 07:44
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 4 reports, 33 attack patterns (mitre), 3 malware, 1 sectors, 1 countries, 50 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (4)
-
6 MITREs 1 Malware 1 APT
-
6 MITREs 1 Malware 12 Observables 1 APT
-
2 Malwares 14 Observables 1 APT
-
8 MITREs 1 Malware 2 Observables 1 APT
Attack patterns (MITRE) (33)
-
T1566.002 usesSpearphishing Link MITRE
-
T1069 usesPermission Groups Discovery MITRE
-
T1059.005 usesVisual Basic MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1566.001 usesSpearphishing Attachment MITRE
-
T1055.012 usesProcess Hollowing MITRE
-
T1027.002 usesSoftware Packing MITRE
-
T1546.008 MITRE
-
T1078 usesValid Accounts MITRE
-
T1059.007 usesJavaScript MITRE
-
T1543.003 usesWindows Service MITRE
-
T1059.004 usesUnix Shell MITRE
Malware (3)
-
GootKit usesFamily
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Gootloader usesThe MITRE Corporation Confidence 100
[Gootloader](https://attack.mitre.org/software/S1138) is a Javascript-based infection framework that has been used since at least 2020 as a delivery method for the Gootkit banking trojan, [Cobalt Strike](https://attack.mitre.org/software/S0154), [REvil](https://attack.mitre.org/software/S0496), and others.…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (1)
-
Technology targets
Countries (1)
-
Australia targets
Indicators (50)
-
435f48667b32c3ab8bb806a8783c0fc40af86e6c5cbf6f621d6e1a3f331483edindicates -
serviciilaser.roindicates -
be3222219f029b47120390b2b1ad46ae86287e64a1f7228d6b2ffd89345a889eindicates -
ledabel.beindicates -
ea781eef1da03ea2c3b5250ce26b00445d8a5123bbb0575c583211cca53c61dbindicates -
climatehero.meindicates -
my-little-kitchen.comindicates -
89672c08916dd38d9d4b7f5bbf7f39f919adcaebc7f8bb1ed053cb701005499aindicates -
wyantgroup.comindicates -
aad75498679aada9ee2179a8824291e3b4781d5683c2fa5b3ec92267ce4a4a33indicates -
fannisho.comindicates -
5f2c97499943878d853332da541138bd6ccbafca7e00d6f90d06545b27b66ca3indicates