ATT&CKSoftwareGootloader

Gootloader

S1138

Malware.View on attack.mitre.org

About this malware

Gootloader is a Javascript-based infection framework that has been used since at least 2020 as a delivery method for the Gootkit banking trojan, Cobalt Strike, REvil, and others. Gootloader operates on an "Initial Access as a Service" model and has leveraged SEO Poisoning to provide access to entities in multiple sectors worldwide including financial, military, automotive, pharmaceutical, and energy.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1016
System Network Configuration Discovery

Gootloader can use an embedded script to check the IP address of potential victims visiting compromised websites.

T1027
Obfuscated Files or Information

The Gootloader first stage script is obfuscated using random alpha numeric strings.

T1055.002
Portable Executable Injection

Gootloader can use its own PE loader to execute payloads in memory.

T1055.012
Process Hollowing

Gootloader can inject its Delphi executable into ImagingDevices.exe using a process hollowing technique.

T1059.001
PowerShell

Gootloader can use an encoded PowerShell stager to write to the Registry for persistence.

T1059.007
JavaScript

Gootloader can execute a Javascript file for initial infection.

T1069.002
Domain Groups

Gootloader can determine if a targeted system is part of an Active Directory domain by expanding the %USERDNSDOMAIN% environment variable.

T1082
System Information Discovery

Gootloader can inspect the User-Agent string in GET request header information to determine the operating system of targeted systems.

T1105
Ingress Tool Transfer

Gootloader can fetch second stage code from hardcoded web domains.

T1132.001
Standard Encoding

Gootloader can retrieve a Base64 encoded stager from C2.

T1140
Deobfuscate/Decode Files or Information

Gootloader has the ability to decode and decrypt malicious payloads prior to execution.

T1204.001
Malicious Link

Gootloader has been executed through malicious links presented to users as internet search results.

T1497.003
Time Based Checks

Gootloader can designate a sleep period of more than 22 seconds between stages of infection.

T1547.001
Registry Run Keys / Startup Folder

Gootloader can create an autorun entry for a PowerShell script to run at reboot.

T1584.001
Domains

Gootloader has used compromised legitimate domains to as a delivery network for malicious payloads.

View all 18 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. SentinelOne Gootloader June 2021 Open source
    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.
  2. Sophos Gootloader Open source
    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.