Gootloader can use an embedded script to check the IP address of potential victims visiting compromised websites.3
tool
Gootloader S1138
- Type
- malware
- Platform
- Windows
- Created
- 28 May 2024
- Last modified
- 19 June 2024
Gootloader is a Javascript-based infection framework that has been used since at least 2020 as a delivery method for the Gootkit banking trojan, Cobalt Strike, REvil, and others. Gootloader operates on an "Initial Access as a Service" model and has leveraged SEO Poisoning to provide access to entities in multiple sectors worldwide including financial, military, automotive, pharmaceutical, and energy.[1][2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S1138
The Gootloader first stage script is obfuscated using random alpha numeric strings.45
Gootloader can use its own PE loader to execute payloads in memory.6
Gootloader can inject its Delphi executable into ImagingDevices.exe using a process hollowing technique.78
Gootloader can use an encoded PowerShell stager to write to the Registry for persistence.910
Gootloader can execute a Javascript file for initial infection.1112
Standing S1138
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
75th percentile · 75% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
68th percentile · 68% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
25th percentile · 75% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S1138
653 distinct rules cover the 18 techniques recorded for this tool. The 783 technique-to-rule mappings resolve to 653 distinct rules, because one rule can cover several techniques. 479 Sigma · 174 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org