
- Gootloader malware resurfaced in late October 2025 after a nine-month hiatus, used to stage ransomware attacks
- Delivered via malicious JavaScript hidden in custom web fonts, enabling stealthy remote access and reconnaissance
- Linked to Storm-0494 and Vice Society; attackers reached domain controllers in under an hour in some cases
After a nine-month sabbatical, the malware known as Gootloader is truly back, possibly being used as a stepping stone towards ransomware infections.