@Gootloaderi
iAccount based inUnited States
About this account
- Account based in
- United States
- Connected via
- United States App Store
Account-level information from X, not a live location or the device used for a specific post.
Security researcher dedicated to pissing off the Gootloader Threat Actor.
Everywhere and nowhere
Joined April 2023
- Tweets2.4K
- Following381
- Followers1.3K
- Likes342
Pinned Tweet
Guess who's back? 🎶
Gootloader's back. Again.
New evasion tricks. New persistence chain. Same legal-themed lures.
Big props to @RussianPanda9xx & @HuntressLabs for catching this one early.
Details: gootloader.wordpress.com/202……
#gootloader #malware #JavaScript #powershell
✅ I acknowledge I have read and understood the information presented
whitehouse.gov/presidential-…
New #OperationEndgame actions revealed.
This time targeting: #StealC
The blip video is hardcore.
1. #StealC Admin stole data from his affiliates/users
2. #StealC was so vulnerable, even Law Enforcement is laughing about them, directly mentioning the exploits being leveraged to steal their stuff.
3. Also a lot of affiliates seem to be named on the number plates of the vehicles, showing #OpEndgame knows exactly who they are up against.
4. Seems Law Enforcement themselves realized that they are only a "Bonus Stage" to ending an already completely broken product XD
I guess we can call this blip
#EndgameLevelTrolling ^^
More links on this in the first comment below.
Gootloader retweeted
🚨 Trojanized CPU-Z → STXRAT → PureLogs Stealer → PureHVNC → 54hrs of exfil through a hidden QEMU VM.
We caught everything after.
First documented full post-exploitation chain for this campaign. IOCs & hunting artifacts link in thread
#ThreatIntel #DFIR #Malware
Gootloader retweeted
Before I was arrested in 2009, I was at the height of my little cybercriminal "empire". I was standing at a crossroads. Part of me wanted an exit and a chance to redirect my skills toward something constructive. Another part of me feared that if I walked away, all the risks I had taken as a hacker would have meant nothing.
11 years in prison for hacking taught me that the reputation I thought I had built in that world, the ideals I believed in, and the status I thought mattered turned out to be far more futile than I could have imagined at the time. When everything collapsed, I realized that none of that mattered. I learned that most of what passes for loyalty and respect in cybercrime is conditional.
Today, there's no reason to turn to cybercrime in order to feel accepted or to enjoy camaraderie and acceptance among peers, or to pursue a sense of justice and vindication. Cybercrime isn't the solution, or the stepping stone.
All the hackers in my crew from back in the day have respectable cybersecurity careers today, because sooner or later everyone learns the same lesson. Cybercrime has limits, and it does not put food on the table without tremendous risk. #realtalk #hacking #hacktivism #truecrime
Anyone have a good way to monitor new @GoogleAds for a specific domain?
Nice write up. #gootloader is known to push Oyster
#OysterLoader (aka #Broomstick or #Cleanup) is not just another downloader. Often serving as a precursor to #Rhysida #ransomware campaigns or distributing commodity malware such as #Vidar, this threat has evolved significantly as we enter 2026.
buff.ly/ZAQuErp
#Reverse
Gootloader retweeted
Jordanian Man Extradited from Georgia Admits Selling Unauthorized Access to Computer Networks of 50 Companies justice.gov/usao-nj/pr/jorda…
Gootloader retweeted
⚠️ GootLoader now uses 500–1,000 ZIP files glued together!
The broken ZIP won’t open in WinRAR or 7-Zip, but Windows Explorer still opens it and runs the JavaScript malware. Each download is different, so file hashes don’t match.
🔗 Learn how this ZIP trick bypasses defenses → thehackernews.com/2026/01/go…
Gootloader retweeted
Gootloader now uses 1,000-part ZIP archives for stealthy delivery - @billtoulas
bleepingcomputer.com/news/se…
bleepingcomputer.com/news/se…
Great write-up on the #gootloader zip! Hopefully with these details @MicrosoftSec will take this seriously and fix their ZIP unarchiver.
Great Yara rule. #100daysofyara
All #Gootloader domains I am aware of & their URLs. github.com/GootloaderSites/F… & github.com/GootloaderSites/F….
Domains protected by @Cloudflare. Whois protected by @gnamedotcom (cc @dowomain @brandomainable). SSL protected by @googlecloud. Reported to @abuse_ch, @google (SB) and @bing
@gnamedotcom @dowomain @brandomainable please act on the domains reported case GW2026010920446794. My reputation, plus what I provided on Friday, should be enough to stop protecting a criminal's infrastructure
Gootloader retweeted
Right before the holidays, I broke the news that DHS had effectively forced out the staffer running CISA's ransomware warning program: cybersecuritydive.com/news/c…
People who worked w/ him are really worried. And we may be starting to see the impact... linkedin.com/feed/update/urn…
New Year’s wish:
#Gootloader hangs up the keyboard so we can all stop running this endless game of cyber cat and mouse.
Let the mouse rest. Let the cat rest. Let me rest.