LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S1138: Gootloader

Gootloader is a Javascript-based infection framework that has been used since at least 2020 as a delivery method for the Gootkit banking trojan, Cobalt Strike, REvil, and others. Gootloader operates on an "Initial Access as a Service" model and has leveraged SEO Poisoning to provide access to entities in multiple sectors worldwide including financial, military, automotive, pharmaceutical, and energy.[1][2]

EnterpriseS1138MalwareObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Gootloader matters because it is described by ATT&CK as a JavaScript-based infection framework and “Initial Access as a Service” delivery method that has used SEO poisoning and has delivered higher-impact follow-on tools such as Gootkit, Cobalt Strike, REvil, and others. For leaders, the decision point is not just “detect this malware,” but whether the organization can recognize a web-driven initial access chain on Windows before it turns into credential theft, hands-on-keyboard activity, or ransomware-enabling access.

Executive priority

Prioritize Gootloader as an initial-access and resilience validation scenario for Windows environments. Ask whether web security, endpoint logging, PowerShell visibility, script controls, identity discovery monitoring, and incident-response playbooks can connect the full chain: user link interaction, JavaScript execution, obfuscation/decoding, payload transfer, discovery, persistence, and possible process injection. This is especially relevant for audit evidence around endpoint monitoring, least privilege, security awareness, and response readiness.

Technical view

ATT&CK provides no official detection text for S1138, so coverage should be validated through the related behaviors. SOC teams should test whether they can correlate Windows JavaScript/JScript execution, PowerShell activity, obfuscated or decoded content, ingress tool transfer, system and network discovery, domain group discovery, time/location/language checks, registry run key or startup-folder persistence, and process injection indicators. Detection should focus on behavior chains rather than a single indicator, because the object is explicitly associated with obfuscation, standard encoding, and analysis-evasion-style checks.

Likely telemetry

  • Windows process creation events with command line and parent/child process context
  • PowerShell execution telemetry, including script block or equivalent command visibility where available
  • Windows Script Host, JScript, or JavaScript execution evidence on endpoints
  • Browser, proxy, DNS, and web gateway logs related to user link clicks, search-result-driven access, downloads, and unusual external connections
  • Endpoint file telemetry for downloaded, obfuscated, encoded, decoded, or newly created script and payload artifacts

Detection direction

  • Validate correlation from malicious-link or SEO-poisoning-style web access into JavaScript execution and PowerShell follow-on activity on Windows hosts.
  • Tune for suspicious script interpreters spawning PowerShell, discovery commands, download activity, or persistence changes, while accounting for legitimate administration scripts and software deployment tooling.
  • Review whether endpoint controls expose process hollowing and PE injection signals; process-only alerting may miss activity when code runs inside another process.
  • Treat obfuscation, standard encoding, and later deobfuscation as detection pivots, not just static signatures.
  • Monitor for domain group discovery and system/network discovery shortly after script execution, because these behaviors may indicate triage of the victim environment before follow-on payloads.

Mitigation priorities

  • Reduce exposure to web-driven initial access with user training, safe browsing controls, download controls, and processes for reporting suspicious search-result or link-driven downloads.
  • Harden Windows script execution and PowerShell usage according to business need, including limiting unnecessary scripting paths and improving logging before enforcement where operational risk is high.
  • Apply application control or allowlisting strategies where feasible to reduce unapproved script and payload execution.
  • Strengthen least privilege and identity hygiene so domain group discovery does not quickly reveal broadly privileged accounts or excessive access paths.
  • Monitor and control persistence locations such as Registry Run Keys and Startup folders, and ensure changes are reviewable during incident response.
Additional notes and limits

This take is based on ATT&CK S1138, its official description, external references, and listed technique relationships. The strongest supported framing is Gootloader as a Windows-focused JavaScript infection framework used for initial-access delivery, with relationships spanning execution, stealth, discovery, command and control, persistence, and resource development.

ATT&CK provides no official detection guidance, no aliases, no object-level tactics, and no indicators in the supplied fields. Local conclusions require environment-specific telemetry, asset context, web/proxy data, endpoint visibility, and incident evidence. Related technique platforms may include non-Windows platforms, but the Gootloader object itself is supplied with Windows as its platform.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Gootloader

Gootloader is a Javascript-based infection framework that has been used since at least 2020 as a delivery method for the Gootkit banking trojan, Cobalt Strike, REvil, and others. Gootloader operates on an "Initial Access as a Service" model and has leveraged SEO Poisoning to provide access to entities in multiple sectors worldwide including financial, military, automotive, pharmaceutical, and energy.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

18 rows
DomainIDNameRelationship / procedure
EnterpriseT1614System Location Discovery

Gootloader can use IP geolocation to determine if the person browsing to a compromised site is within a targeted territory such as the US, Canada, Germany, and South Korea.[2]

EnterpriseT1584.001DomainsSub-technique

Gootloader has used compromised legitimate domains to as a delivery network for malicious payloads.[2]

EnterpriseT1069.002Domain GroupsSub-technique

Gootloader can determine if a targeted system is part of an Active Directory domain by expanding the %USERDNSDOMAIN% environment variable.[2]

EnterpriseT1584.006Web ServicesSub-technique

Gootloader can insert malicious scripts to compromise vulnerable content management systems (CMS).[2]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Gootloader can create an autorun entry for a PowerShell script to run at reboot.[1]

EnterpriseT1059.001PowerShellSub-technique

Gootloader can use an encoded PowerShell stager to write to the Registry for persistence.[1][2]

EnterpriseT1497.003Time Based ChecksSub-technique

Gootloader can designate a sleep period of more than 22 seconds between stages of infection.[1]

EnterpriseT1614.001System Language DiscoverySub-technique

Gootloader can determine if a victim's computer is running an operating system with specific language preferences.[1]

EnterpriseT1204.001Malicious LinkSub-technique

Gootloader has been executed through malicious links presented to users as internet search results.[1][2]

EnterpriseT1082System Information Discovery

Gootloader can inspect the User-Agent string in GET request header information to determine the operating system of targeted systems.[1]

EnterpriseT1140Deobfuscate/Decode Files or Information

Gootloader has the ability to decode and decrypt malicious payloads prior to execution.[1][2]

EnterpriseT1059.007JavaScriptSub-technique

Gootloader can execute a Javascript file for initial infection.[1][2]

EnterpriseT1055.002Portable Executable InjectionSub-technique

Gootloader can use its own PE loader to execute payloads in memory.[1]

EnterpriseT1055.012Process HollowingSub-technique

Gootloader can inject its Delphi executable into ImagingDevices.exe using a process hollowing technique.[1][2]

EnterpriseT1016System Network Configuration Discovery

Gootloader can use an embedded script to check the IP address of potential victims visiting compromised websites.[2]

EnterpriseT1132.001Standard EncodingSub-technique

Gootloader can retrieve a Base64 encoded stager from C2.[2]

EnterpriseT1105Ingress Tool Transfer

Gootloader can fetch second stage code from hardcoded web domains.[1][2]

EnterpriseT1027Obfuscated Files or Information

The Gootloader first stage script is obfuscated using random alpha numeric strings.[1][2]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
667c46923223eb42...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.0Current bundle667c46923223…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  2. [2]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  3. [3]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  4. [4]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  5. [5]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  6. [6]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  7. [7]
    mitre-attackS1138
    Open source URL
  8. [8]
    mitre-attackS1138
    Open source URL
  9. [9]
    mitre-attackS1138
    Open source URL
  10. [10]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  11. [11]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  12. [12]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  13. [13]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  14. [14]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  15. [15]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  16. [16]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  17. [17]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  18. [18]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  19. [19]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  20. [20]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  21. [21]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  22. [22]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  23. [23]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  24. [24]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  25. [25]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  26. [26]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  27. [27]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  28. [28]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  29. [29]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  30. [30]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  31. [31]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  32. [32]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  33. [33]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  34. [34]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  35. [35]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  36. [36]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  37. [37]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  38. [38]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  39. [39]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  40. [40]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  41. [41]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  42. [42]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  43. [43]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  44. [44]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  45. [45]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  46. [46]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  47. [47]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  48. [48]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  49. [49]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  50. [50]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  51. [51]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  52. [52]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  53. [53]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  54. [54]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  55. [55]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
  56. [56]
    SentinelOne Gootloader June 2021

    Pirozzi, A. (2021, June 16). Gootloader: ‘Initial Access as a Service’ Platform Expands Its Search for High Value Targets. Retrieved May 28, 2024.

    Open source URL
  57. [57]
    Sophos Gootloader

    Szappanos, G. & Brandt, A. (2021, March 1). “Gootloader” expands its payload delivery options. Retrieved September 30, 2022.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.