HomeSecurityGootLoader: New hiding technique on WordPress websites

GootLoader: New hiding technique on WordPress websites

The malware known as GootLoader has resurfaced after a brief spike in activity last March, according to findings from Huntress. The cybersecurity firm observed three GootLoader infections since October 27, 2025, two of which led to direct keystroke crunching and domain controller compromise attacks within 17 hours of the initial infection.

See also: Vulnerability in WordPress Post SMTP plugin – 400,000 sites at risk 

GootLoader

“GootLoader is back and now leverages custom WOFF2 fonts with character substitution to obfuscate filenames,” said security researcher Anna Pham, adding that the malware “exploits WordPress comment points to deliver XOR-encrypted ZIP payloads, with unique keys per file.”

GootLoader, associated with a threat actor tracked as Hive0127 (also known as UNC2565), is a JavaScript-based loader malware that is often distributed via search engine optimization (SEO) poisoning tactics to deliver additional payloads, including ransomware. In a report published last September, Microsoft revealed that the threat actor referred to as Vanilla Tempest receives deliveries from GootLoader infections from the Storm-0494 threat actor, leveraging access to install a backdoor called Supper (also known as SocksShell or ZAPCAT), as well as AnyDesk for remote access.

These attack chains have led to the development of the INC ransomware. It is worth noting that Supper has also been linked to the Interlock RAT (also known as NodeSnake), another malware that is primarily associated with the Interlock ransomware. “While there is no direct evidence that Interlock uses Supper, both Interlock and Vice Society have been linked to Rhysida at different times, suggesting possible overlaps in the broader cybercriminal ecosystem,” Foresecout noted last month.

See also: Service Finder: Hackers exploit vulnerability in WordPress theme

GootLoader: New hiding technique on WordPress websites

Earlier this year, the threat actor behind GootLoader was found to be leveraging Google ads to target victims searching for legal templates, such as agreements, in search engines to redirect them to compromised WordPress websites hosting malware-laden ZIP files. The latest attack sequence documented by Huntress shows that searches for terms like “missouri cover utility easement roadway” on Bing are being used to direct unsuspecting users to hand over the ZIP file.

This time, a custom web font is used to hide the filenames displayed in the browser to defeat static analysis methods. “So when the user tries to copy the filename or inspect the source code – they will see strange characters,” Pham explained.

A new trick was also observed that modifies the ZIP file so that when opened with tools such as VirusTotal, Python’s ZIP tools, or 7-Zip, it unzips as a harmless .TXT file. In Windows File Explorer, the file unzips a valid JavaScript file, which is the intended payload. “This simple evasion technique buys the attacker time by hiding the true nature of the payload from automated analysis,” a security researcher who has been tracking malware for a long time under the alias “GootLoader,” said about the development. The JavaScript payload contained within the file is designed to deploy Supper, a backdoor capable of remote control and SOCKS5 mediation.

See also: Sophisticated malware campaign targets WordPress websites

GootLoader: New hiding technique on WordPress websites

In at least one case, threat actors are said to have used WinRM to move laterally to the Domain Controller and create a new user with administrator-level access.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS