← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
GootLoader New Evasion Methods Target Search Driven Workflows
GootLoader, operated by the threat group UNC2565 (also known as Storm-0494), has resurfaced with advanced techniques to exploit search-driven workflows. This malware loader is central to a sophisticated Access-as-a-Service platform that facilitates initial access for ransomware affiliates, including Vanilla Tempest, and leverages SEO poisoning to attract users searching for business document templates. A notable attack technique involves the use of a dual-personality ZIP archive. This archive is engineered to deceive security sandboxes by appearing harmless while extracting a malicious .js file for human users. Upon execution, usually triggered by the user double-clicking the JScript file, the payload launches through Windows Script Host, specifically WScript.exe or CScript.exe, which in turn invokes PowerShell to retrieve subsequent malicious payloads.
MITRE ATT&CK & Malware Families
Indicators of Compromise (10 / 146 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-SHA256 | 2f056ce0657542da3e7e43fb815a8973c354624043f19ef134dff271db1741b3 | — | 2025-11-08 | |
| FileHash-SHA256 | 5ec9e926d4fb4237cf297d0d920cf0e9a5409f0226ee555bd8c89b97a659f4b0 | — | 2025-11-08 | |
| FileHash-SHA256 | 7557d5fed880ee1e292aba464ffdc12021f9acbe0ee3a2313519ecd7f94ec5c4 | — | 2025-11-08 | |
| FileHash-SHA256 | 87cbe9a5e9da0dba04dbd8046b90dbd8ee531e99fd6b351eae1ae5df5aa67439 | — | 2025-11-08 | |
| FileHash-SHA256 | a79eaf53a4b42e80d9ecdb8b139e9dc812cedf063153da3f8a2b7a49bc7b81d4 | — | 2025-11-08 | |
| FileHash-SHA256 | ad88076fd75d80e963d07f03d7ae35d4e55bd49634baf92743eece19ec901e94 | — | 2025-11-08 | |
| FileHash-SHA256 | b9a61652dffd2ab3ec3b7e95829759fc43665c27e9642d4b2d4d2f7287254034 | — | 2025-11-08 | |
| FileHash-SHA256 | c2326db8acae0cf9c5fc734e01d6f6c1cd78473b27044955c5761ec7fd479964 | — | 2025-11-08 | |
| FileHash-SHA256 | c2b9782c55f75bb1797cb4fbae0290b44d0fcad51bf4f2c11c52ebbe3526d2ac | — | 2025-11-08 | |
| FileHash-SHA256 | cf44aa11a17b3dad61cae715f4ea27c0cbf80732a1a7a1c530a5c9d3d183482a | — | 2025-11-08 |