Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Gootloader malware returns with fake NDA scam – here’s what we know

Tech Wavo by Tech Wavo
November 6, 2025
in Computers
0



  • Gootloader malware resurfaces using malvertising and SEO poisoning to spread infections
  • Attackers now obfuscate malware names using deceptive web fonts and glyph swapping
  • Loader delivers ransomware, infostealers, and Cobalt Strike via compromised search results

The Gootloader malware scam, which was thought to have been disrupted and shut down in March 2025, has returned with both old, and new tricks, experts have warned.

Gootloader is known for using malvertising and SEO poisoning to distribute the malware. Cybercriminals would either create websites, or infiltrate legitimate ones, and rearrange them to host different documents, such as NDA templates. Then they would purchase ads on popular ad networks, or engage in SEO poisoning – creating countless web articles and filling them up with keywords linking back to the sites under their control.

Analysts from Huntress Labs claim to have seen hundreds of websites hosting the malware, noted a combination of these two practices means when people search for different terms, these malicious websites would pop up at the very top of search engine results, instead of actual legitimate pages, increasing the chances of compromise.


You may like

Obfuscation techniques

The campaign was effectively terminated in March 2025, after continuous pressure from security researchers towards ISPs and hosting platforms resulted in the takedown of the attackers’ infrastructure.

Now, after a half-year hiatus, Gootloader is back, using the same techniques to deploy the loader which, in turn, serves different ransomware, infostealers, or Cobalt Strike beacons.

The biggest difference is in new obfuscation techniques, the researchers said. Using JavaScript, the attackers would hide real file names of the malware, by using a special web font that replaces characters with symbols who look the same. In the HTML source, a researcher might see gibberish, but when the page is rendered, the symbols would display normal words.

“Rather than using OpenType substitution features or character mapping tables, the loader swaps what each glyph actually displays. The font’s metadata appears completely legitimate—the character “O” maps to a glyph named “O”, the character “a” maps to a glyph named “a”, and so forth,” Huntress said.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

“However, the actual vector paths that define these glyphs have been swapped. When the browser requests the shape for glyph “O”, the font provides the vector coordinates that draw the letter “F” instead. Similarly, “a” draws “l”, “9” draws “o”, and special Unicode characters like “±” draw “i”. The gibberish string Oa9Z±h• in the source code renders as “Florida” on screen.”

Via BleepingComputer


Best antivirus software header

The best antivirus for all budgets

Our top picks, based on real-world testing and comparisons

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Previous Post

The New York Times is letting you create your own Wordle puzzles

Next Post

The 15-Inch MacBook Air Is Marked Down by $200

Next Post
The 15-Inch MacBook Air Is Marked Down by $200

The 15-Inch MacBook Air Is Marked Down by $200

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Rise of Hydra has been delayed with no new release window

by Tech Wavo
November 7, 2025
0
Rise of Hydra has been delayed with no new release window
Computers

Marvel 1943: Rise of Hydra has been delayed again. The project had already been pushed back in May from a...

Read more

Tesla delays reveal of production Roadster 2 to April Fools’ Day

by Tech Wavo
November 7, 2025
0
Tesla delays reveal of production Roadster 2 to April Fools’ Day
Computers

Tesla CEO Elon Musk said Thursday the company will reveal the production version of its second-generation Roadster supercar on April...

Read more

Fed up with Windows 11’s clunky right-click menu? Microsoft just dropped a hint that it could become more streamlined

by Tech Wavo
November 7, 2025
0
Fed up with Windows 11’s clunky right-click menu? Microsoft just dropped a hint that it could become more streamlined
Computers

Microsoft is working on streamlining Windows 11's right-click menusThis is just for the context-sensitive options available to apps, thoughHowever, the...

Read more

Tesla shareholders approve Elon Musk’s $1 trillion compensation package

by Tech Wavo
November 6, 2025
0
Tesla shareholders approve Elon Musk’s $1 trillion compensation package
Computers

Tesla’s shareholders have voted in favor of a compensation plan that could see CEO Elon Musk become the world's first...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock