Attention WordPress Users: GootLoader Strikes Again Using Font Hijacking to Spread Malware


  • Gootloader malware resurfaced in late October 2025 after a nine-month hiatus, used to stage ransomware attacks
  • Delivered via malicious JavaScript hidden in custom web fonts, allowing stealthy remote access and recognition
  • Related to Storm-0494 and Vice Society; attackers reached domain controllers in less than an hour in some cases

After a nine-month sabbatical, the malware known as Gootloader is truly back, perhaps used as a springboard to ransomware infections.

A report from cybersecurity researchers Huntress observed “multiple infections” from October 27 to early November 2025. Before that, the last time Gootloader was seen was in March 2025.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top