News

GootLoader uses malformed ZIP files to bypass security controls

  • Pierluigi Paganini--Securityaffairs.com
  • published date: 2026-01-18 18:22:16 UTC

GootLoader malware uses malformed ZIP files made of hundreds of concatenated archives to evade detection. GootLoader is used by ransomware actors for initial access, then handed off to others. Built to evade detection, it accounted for 11% of bypassing malwar…

GootLoader uses malformed ZIP files to bypass security controls GootLoader is used by ransomware actors for initial access, then handed off to others. Built to evade detection, it accounted for 11% … [+4491 chars]