WordPress users beware – GootLoader strikes again, using font hack to spread malware



  • Gootloader malware resurfaced in late October 2025 after a nine-month hiatus, used to stage ransomware attacks
  • Delivered via malicious JavaScript hidden in custom web fonts, enabling stealthy remote access and reconnaissance
  • Linked to Storm-0494 and Vice Society; attackers reached domain controllers in under an hour in some cases

After a nine-month sabbatical, the malware known as Gootloader is truly back, possibly being used as a stepping stone towards ransomware infections.

A report from cybersecurity researchers Huntress observed “multiple infections” from October 27 and into early November, 2025. Before that, the last time Gootloader was seen was in March, 2025.





Source link

The post WordPress users beware – GootLoader strikes again, using font hack to spread malware first appeared on TechToday.

This post originally appeared on TechToday.

Leave a Reply

Your email address will not be published. Required fields are marked *