By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection
Computing

GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection

News Room
Last updated: 2026/01/16 at 1:39 PM
News Room Published 16 January 2026
Share
GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection
SHARE

Jan 16, 2026Ravie LakshmananMalvertising / Threat Intelligence

The JavaScript (aka JScript) malware loader called GootLoader has been observed using a malformed ZIP archive that’s designed to sidestep detection efforts by concatenating anywhere from 500 to 1,000 archives.

“The actor creates a malformed archive as an anti-analysis technique,” Expel security researcher Aaron Walton said in a report shared with The Hacker News. “That is, many unarchiving tools are not able to consistently extract it, but one critical unarchiving tool seems to work consistently and reliably: the default tool built into Windows systems.”

This leads to a scenario where the archive cannot be processed by tools like WinRAR or 7-Zip, and, therefore, prevents many automated workflows from analyzing the contents of the file. At the same time, it can be opened by the default Windows unarchiver, thereby ensuring that victims who fall victim to the social engineering scheme can extract and run the JavaScript malware.

GootLoader is typically distributed via search engine optimization (SEO) poisoning tactics or malvertising, targeting users looking for legal templates to take them to compromised WordPress sites hosting malicious ZIP archives. Like other loaders, it’s designed to deliver secondary payloads, including ransomware. The malware has been detected in the wild since at least 2020.

Cybersecurity

In late October 2025, malware campaigns propagating the malware resurfaced with new tricks: leveraging custom WOFF2 fonts with glyph substitution to obfuscate filenames and exploiting the WordPress comment endpoint (“/wp-comments-post.php”) to deliver the ZIP payloads when a user clicks a “Download” button on the site.

The latest findings from Expel highlight continued evolution of the delivery methods, with the threat actors employing more sophisticated obfuscation mechanisms to evade detection –

  • Concatenate together 500-1,000 archives to craft the malicious ZIP file
  • Truncate the archive’s end of central directory (EOCD) record such that it misses two critical bytes from the expected structure, triggering parsing errors
  • Randomize values in non-critical fields, such as disk number and Number of Disks, causing unarchiving tools to expect a sequence of ZIP archives that are non-existent

“The random number of files concatenated together, and the randomized values in specific fields are a defense-evasion technique called ‘hashbusting,'” Walton explained.

“In practice, every user who downloads a ZIP file from GootLoader’s infrastructure will receive a unique ZIP file, so looking for that hash in other environments is futile. The GootLoader developer uses hashbusting for the ZIP archive and for the JScript file contained in the archive.”

The attack chain essentially involves the delivery of the ZIP archive as an XOR-encoded blob, which is decoded and repeatedly appended to itself on the client-side (i.e., on the victim’s browser) until it meets a set size, effectively bypassing security controls designed to detect the transmission of a ZIP file.

Cybersecurity

As soon as the downloaded ZIP archive is double-clicked by the victim, it will cause Windows’ default unarchiver to open the ZIP folder containing the JavaScript payload in File Explorer. Launching the JavaScript file, in turn, triggers its execution via “wscript.exe” from a temporary folder, since the file contents were not explicitly extracted.

The JavaScript malware then creates a Windows shortcut (LNK) file in the Startup folder to establish persistence, ultimately executing a second JavaScript file using cscript, spawning PowerShell commands to take the infection to the next stage. In previous GootLoader attacks, the PowerShell script is used to collect system information and receive commands from a remote server.

To counter the threat posed by GootLoader, organizations are advised to consider blocking “wscript.exe” and “cscript.exe” from executing downloaded content if not required and use a Group Policy Object (GPO) to ensure that JavaScript files are opened in Notepad by default, instead of executing them via “wscript.exe.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Mayor of London Sadiq Khan calls for urgent action to boost the capital’s AI workforce | Computer Weekly Mayor of London Sadiq Khan calls for urgent action to boost the capital’s AI workforce | Computer Weekly
Next Article Ring camera gets price drop to £39.99 & it has bonus trick for anyone with pets Ring camera gets price drop to £39.99 & it has bonus trick for anyone with pets
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Inside the radical hypercar that you could soon drive – but not in real life
Inside the radical hypercar that you could soon drive – but not in real life
News
So You’ve Decided To Do a Technical Migration
So You’ve Decided To Do a Technical Migration
News
MacBook Neo benchmark results are predictably close to iPhone 16 Pro, M1 comparable
MacBook Neo benchmark results are predictably close to iPhone 16 Pro, M1 comparable
News
Big Tech Promises to Pay for AI Data Center Power, but Who Will Enforce It?
Big Tech Promises to Pay for AI Data Center Power, but Who Will Enforce It?
News

You Might also Like

China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom Attacks
Computing

China-Linked Hackers Use TernDoor, PeerTime, BruteEntry in South American Telecom Attacks

5 Min Read
LICURV explores instant kitchen cleaning with compact dishwasher and five-second wash · TechNode
Computing

LICURV explores instant kitchen cleaning with compact dishwasher and five-second wash · TechNode

4 Min Read
Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog
Computing

Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog

2 Min Read
Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer
Computing

Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?