GootLoader malware has resurfaced, utilizing custom fonts to obscure filenames on WordPress sites, complicating detection. It exploits SEO tactics and comment endpoints to deliver encrypted payloads, often leading to domain controller compromises. The malware has evolved to disguise its true nature, using deceptive techniques to evade automated analysis and remains tied to a broader cybercriminal ecosystem involving various threat actors.
https://thehackernews.com/2025/11/gootloader-is-back-using-new-font-trick.html

