Get all your news in one place.
100's of premium titles.
One app.
Start reading
TechRadar
TechRadar
Sead Fadilpašić

WordPress users beware - GootLoader strikes again, using font hack to spread malware

WordPress logo on mobile.
  • Gootloader malware resurfaced in late October 2025 after a nine-month hiatus, used to stage ransomware attacks
  • Delivered via malicious JavaScript hidden in custom web fonts, enabling stealthy remote access and reconnaissance
  • Linked to Storm-0494 and Vice Society; attackers reached domain controllers in under an hour in some cases

After a nine-month sabbatical, the malware known as Gootloader is truly back, possibly being used as a stepping stone towards ransomware infections.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.