Initially detailed in December 2020, GootLoader is a piece of initial access malware, allowing its operators to deploy various other malware families – including ransomware – on the compromised machines.
Over the past few weeks, the GootLoader hacking group has focused mainly on targeting individuals at law and accounting firms, with the most recent attack observed on January 6. eSentire says it has intercepted three such attacks so far.
Potential victims are lured to compromised legitimate websites containing hundreds of pages of business-specific content – including free samples of documents for download – where they end up infected with GootLoader instead.