216.73.216.6

Gootloader Returns: Malware Hidden in Google Ads for Legal Documents

· Published 03/04/2025 22:07 · Modified 04/04/2025 08:32

Export JSON

Essential information

Published
03/04/2025 22:07
Modified
04/04/2025 08:32
Tags
2025-04-03 email phishing google ads gootloader javascript legal templates powershell scheduled tasks social engineering wordpress blogs
Related entities
1 intrusion sets (apt), 6 techniques (mitre), 1 malware

Description

The malware campaign has evolved its tactics, now using to target victims seeking . The threat actor advertises legal documents, primarily agreements, through compromised ad accounts. Users searching for templates are directed to a malicious website where they are prompted to enter their email address. They then receive an email with a link to download a seemingly legitimate document, which is actually a zipped .JS file containing malware. When executed, the malware creates a scheduled task and uses to communicate with compromised . The campaign demonstrates a shift in 's strategy, moving from poisoned search results to controlled infrastructure for malware delivery.

External references