"Gootloader Aims Malicious, Custom Bot Army at Enterprise Networks"
"Gootloader Aims Malicious, Custom Bot Army at Enterprise Networks"
The Gootloader Group is using GootBot, a new destructive post-compromise tool that spreads bots throughout enterprise environments following infiltration. According to researchers with the IBM X-Force threat intelligence group, Gootloader has been active since 2014 and uses Search Engine Optimization (SEO) poisoning to trick victims into downloading infected business document templates for initial compromise.