Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

This lifetime AI-powered piano app teaches you as you play for $99.97 during Deal Day.

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » GootLoader malware uses 500 to 1,000 concatenated ZIP archives to evade detection
Celebrities

GootLoader malware uses 500 to 1,000 concatenated ZIP archives to evade detection

By January 16, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

January 16, 2026Ravi LakshmananMalvertising/Threat Intelligence

A JavaScript (also known as JScript) malware loader called GootLoader has been observed using malicious ZIP archives designed to evade detection efforts by concatenating 500 to 1,000 archives.

“Adversaries are creating fraudulent archives as an anti-analysis technique,” Aaron Walton, a security researcher at Expel, said in a report shared with Hacker News. “In short, while many decompression tools consistently fail to extract files, one important decompression tool seems to work consistently and reliably: the default tool built into Windows systems.”

This prevents tools such as WinRAR and 7-Zip from processing the archive, and many automated workflows from analyzing the file contents. At the same time, it can be opened with the default Windows unarchive, allowing victims of social engineering schemes to extract and run JavaScript malware.

GootLoader is typically distributed via search engine optimization (SEO) poisoning tactics and malvertising, targeting users looking for legitimate templates and redirecting them to compromised WordPress sites that host malicious ZIP archives. Like other loaders, it is designed to deliver secondary payloads, including ransomware. This malware has been detected in the wild since at least 2020.

cyber security

In late October 2025, malware campaigns propagating malware resurfaced with new techniques. It leverages a custom WOFF2 font with glyph substitution to obfuscate filenames and exploits the WordPress comments endpoint (‘/wp-comments-post.php’) to deliver a ZIP payload when a user clicks the site’s ‘Download’ button.

Expel’s latest findings highlight the continued evolution of delivery methods, with attackers employing more sophisticated obfuscation mechanisms to evade detection.

Concatenates 500 to 1,000 archives to create a malicious ZIP file Truncates the archive’s End of Central Directory (EOCD) record, missing two critical bytes from the expected structure, causing parsing errors Randomizes the values ​​of non-critical fields such as disk number and number of disks, causing unzipping tools to expect a series of ZIP archives where none exists

“Concatenating a random number of files and filling certain fields with random values ​​is a defense evasion technique called ‘hashbusting,'” Walton explained.

“In reality, every user who downloads a ZIP file from GootLoader’s infrastructure will receive a unique ZIP file, so looking for its hash in other environments is futile. GootLoader’s developers use hashbusting for ZIP archives and the JScript files they contain.”

The attack chain essentially involves a ZIP archive being delivered as an XOR encoded BLOB. This blob is decoded and appended repeatedly on the client side (i.e., the victim’s browser) until it reaches a set size, effectively bypassing security controls designed to detect ZIP file submissions.

cyber security

As soon as the downloaded ZIP archive is double-clicked by the victim, Windows’ default unzipping feature opens the ZIP folder containing the JavaScript payload in File Explorer. Launching a JavaScript file triggers its execution via ‘wscript.exe’ from a temporary folder, as the file contents are not explicitly extracted.

The JavaScript malware then creates a Windows Shortcut (LNK) file in the startup folder to establish persistence and finally uses cscript to run a second JavaScript file and generate PowerShell commands to proceed to the next stage of the infection. Previous GootLoader attacks used PowerShell scripts to gather system information and receive commands from remote servers.

To combat the threat posed by GootLoader, organizations are encouraged to consider blocking ‘wscript.exe’ and ‘cscript.exe’ from running downloaded content when not required, and consider using Group Policy Objects (GPOs) to ensure that JavaScript files are opened in Notepad by default rather than being executed via ‘wscript.exe’.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleA hacking campaign targeting prominent Gmail and WhatsApp users across the Middle East
Next Article Trump administration is asking technology companies to buy power plants they may not use for $15 billion

Related Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

This lifetime AI-powered piano app teaches you as you play for $99.97 during Deal Day.

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Trending Posts

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

June 16, 2026

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

June 16, 2026

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

June 15, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.