More

    WordPress users beware – GootLoader strikes again, using font hack to spread malware



    • Gootloader malware resurfaced in late October 2025 after a nine-month hiatus, used to stage ransomware attacks
    • Delivered via malicious JavaScript hidden in custom web fonts, enabling stealthy remote access and reconnaissance
    • Linked to Storm-0494 and Vice Society; attackers reached domain controllers in under an hour in some cases

    After a nine-month sabbatical, the malware known as Gootloader is truly back, possibly being used as a stepping stone towards ransomware infections.

    A report from cybersecurity researchers Huntress observed “multiple infections” from October 27 and into early November, 2025. Before that, the last time Gootloader was seen was in March, 2025.


    https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-970-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    spot_imgspot_img