1 min read

The Gootkit Information Stealer

Featured Image

The Gootkit Information Stealer

Ignore the adorable tree baby. This isn't about Groot. It's about Gootkit, a particularly nasty information stealer that's currently being distributed to people via hacked WordPress sites and malicious SEO techniques.

Gootkit, or Gootloader, has been around for awhile; since at least 2019. The bad actors have set up a system that's really pretty...smart? I hate saying that, but as a marketing guy who understands the buyer's journey and how people use the internet, specifically Google, to find what they're looking for.

So, basically, as I'm sure you know, when you're going online to find an answer to a question you have, you're probably using something called a "phrase-based" search. You ask Google a question. It tries to serve up the best answer. You scan your results and click the best match. Yadda, yadda, yadda, you get it.

The people behind Gootkit get this. So they've set up a slew of blank forums on compromised WordPress sites that leverage SEO and an authoritative entry from what appears to be a system administrator or a trusted poster, that contains a masked yet malicious link, and you're off to the races.

After clicking the link, you'll download a ZIP archive. The archive contains a JavaScript file that begins the infection process. The Javascript itself is written to the actual disk. The ransomware is deployed to system memory, making it much more difficult to detect.

The actors are specifically targeting people in the U.S., Germany and South Korea.

The story is still developing so information is still coming out. Sophos has done a really nice write up on the more technical details (which you can read here).

Like our blog? Subscribe using the CTA in the upper right-hand corner of this page. Feel like sharing your thoughts with us? Use the comment section below.

Are Passkeys the Future? Apple Seems to Think So...

It's no secret that passwords are a pain in the butt. They can be difficult to remember, they're a huge target for cybercriminals, etc.

Read More

Alert: Follina aka CVE-2022-30190

A newly discovered exploit is using a flaw in Microsoft's Support Diagnostic Tool (MSDT) to remotely take over end-points via compromised Word...

Read More

Chaos/Yashma: The Torrid Tale of a GUI Based Ransomware Builder...

It used to take a good deal of coding knowledge to build a website or an application. That's not the case anymore. You can build a website in...

Read More