@Gootloader

Security researcher dedicated to pissing off the Gootloader Threat Actor.

Everywhere and nowhere
Joined April 2023
Anyone going to be in Vegas the next few days?
3
172
Gootloader retweeted
New #OperationEndgame actions revealed. This time targeting: #StealC The blip video is hardcore. 1. #StealC Admin stole data from his affiliates/users 2. #StealC was so vulnerable, even Law Enforcement is laughing about them, directly mentioning the exploits being leveraged to steal their stuff. 3. Also a lot of affiliates seem to be named on the number plates of the vehicles, showing #OpEndgame knows exactly who they are up against. 4. Seems Law Enforcement themselves realized that they are only a "Bonus Stage" to ending an already completely broken product XD I guess we can call this blip #EndgameLevelTrolling ^^ More links on this in the first comment below.
5
29
2
120
24,318
2
1
24
2,174
Gootloader retweeted
🚨 Trojanized CPU-Z → STXRAT → PureLogs Stealer → PureHVNC → 54hrs of exfil through a hidden QEMU VM. We caught everything after. First documented full post-exploitation chain for this campaign. IOCs & hunting artifacts link in thread #ThreatIntel #DFIR #Malware
3
22
1
98
8,074
Gootloader retweeted
Before I was arrested in 2009, I was at the height of my little cybercriminal "empire". I was standing at a crossroads. Part of me wanted an exit and a chance to redirect my skills toward something constructive. Another part of me feared that if I walked away, all the risks I had taken as a hacker would have meant nothing. 11 years in prison for hacking taught me that the reputation I thought I had built in that world, the ideals I believed in, and the status I thought mattered turned out to be far more futile than I could have imagined at the time. When everything collapsed, I realized that none of that mattered. I learned that most of what passes for loyalty and respect in cybercrime is conditional. Today, there's no reason to turn to cybercrime in order to feel accepted or to enjoy camaraderie and acceptance among peers, or to pursue a sense of justice and vindication. Cybercrime isn't the solution, or the stepping stone. All the hackers in my crew from back in the day have respectable cybersecurity careers today, because sooner or later everyone learns the same lesson. Cybercrime has limits, and it does not put food on the table without tremendous risk. #realtalk #hacking #hacktivism #truecrime
6
15
1
129
25,964
Anyone have a good way to monitor new @GoogleAds for a specific domain?
2
1
2
561
Nice write up. #gootloader is known to push Oyster
#OysterLoader (aka #Broomstick or #Cleanup) is not just another downloader. Often serving as a precursor to #Rhysida #ransomware campaigns or distributing commodity malware such as #Vidar, this threat has evolved significantly as we enter 2026. buff.ly/ZAQuErp #Reverse
1
11
719
This was a fun one to dig into Confirmed exploitation requires: • User registration enabled • LA-Studio Element Kit = 1.5.6.3 • At least one published Elementor page PoC confirmed (details withheld). Nice find by Jitlada. Boeing777 & Waris Damkham!
1
3
545
⚠️ GootLoader now uses 500–1,000 ZIP files glued together! The broken ZIP won’t open in WinRAR or 7-Zip, but Windows Explorer still opens it and runs the JavaScript malware. Each download is different, so file hashes don’t match. 🔗 Learn how this ZIP trick bypasses defenses → thehackernews.com/2026/01/go…
5
36
120
13,852
Great write-up on the #gootloader zip! Hopefully with these details @MicrosoftSec will take this seriously and fix their ZIP unarchiver. Great Yara rule. #100daysofyara
Gootloader malware returned in November after a hiatus. They work with Vanilla Tempest (currently using Rhysida ransomware). We took a deep look at their first-stage delivery mechanism—a deliberately broken ZIP archive designed to bypass detection. (1/12)
4
41
5,317
I feel this was a major success! Thanks all
1
6
217
@gnamedotcom @dowomain @brandomainable please act on the domains reported case GW2026010920446794. My reputation, plus what I provided on Friday, should be enough to stop protecting a criminal's infrastructure
1
1
115
Gootloader retweeted
Right before the holidays, I broke the news that DHS had effectively forced out the staffer running CISA's ransomware warning program: cybersecuritydive.com/news/c… People who worked w/ him are really worried. And we may be starting to see the impact... linkedin.com/feed/update/urn…
8
302
7
711
47,557
New Year’s wish: #Gootloader hangs up the keyboard so we can all stop running this endless game of cyber cat and mouse. Let the mouse rest. Let the cat rest. Let me rest.
1
10
1,459