Story perspectives
New Gootloader Malware Bypasses Detection with Unique ZIP Technique
1/17/2026
1 of 1
Story summary
- Gootloader uses a malformed ZIP with 500 to 1,000 concatenated archives to bypass detection by forensic tools, unreadable to WinRAR and 7-Zip but readable with Windows' default unarchiver.
- The malware, used in ransomware campaigns, executes a JScript payload that persists via Startup folder shortcut.
- Expel researchers cite hashbusting and randomized metadata that complicate detection.
- To mitigate risk, organizations should block script execution and monitor for unusual .LNK file creation.
