GootLoader Is Back, Using a New Font Trick to Hide Malware on WordPress Sites

Nov 11, 2025

The malware known as GootLoader has resurfaced yet again after a brief spike in activity earlier this March, according to new findings from Huntress.
The cybersecurity company said it observed three GootLoader infections since October 27, 2025, out of which two resulted in hands-on keyboard intrusions with domain controller compromise taking place within 17 hours of initial infection.

Get Free Report & Network Analysis

Please check your email for the free report.