---
title: "Threat Intel Content Update: 11/11/2025"
description: Tidal Cyber's Threat Intelligence Content updates for the week of 11/11/25 - Gootloader Malware 2025 Resurgence
---

[Threat Intelligence Content Updates ](https://www.tidalcyber.com/threat-updates)

# [Threat Intel Content Update: 11/11/2025](https://www.tidalcyber.com/threat-updates/threat-intel-content-update-11/11/2025)

 Written by [Tidal Cyber](https://www.tidalcyber.com/threat-updates/author/tidal-cyber) | Nov 11, 2025 5:06:02 PM

> We officially surpassed 22,000 Procedure Sightings in the Tidal Cyber Knowledge Base (launched with 21k in late July). We will add the next 1,000 considerably faster.

 

#### **Gootloader 2025 Resurgence**

We recently added rich threat & TTP intelligence around widely relevant, trending adversary activity. [Gootloader](https://app.tidalcyber.com/software/b18a505f-16ca-5b51-9bed-ae05b47c7706?tab=2) is a sophisticated, JavaScript-based “loader” malware. Multiple phases of heavy Gootloader use have been observed since 2020, with periods of inactivity in between. In the past week, [multiple](https://gootloader.wordpress.com/2025/11/05/gootloader-is-back-back-again/) [sources](https://www.huntress.com/blog/gootloader-threat-detection-woff2-obfuscation) reported a resurgence in Gootloader attacks since late October.

Gootloader campaigns are relevant to a wide variety of organizations because of the malware’s operating model. Threat actor [Storm-0494](https://app.tidalcyber.com/groups/aa351f3d-b917-45c9-a99e-2fe5ef23a970?tab=3) carries out the initial Gootloader attack, seeking to infect a wide range of victims, then hands off access to the most valuable targets to [Vanilla Tempest](https://app.tidalcyber.com/groups/efd2fca2-45fb-4eaf-82e7-0d20c156f84f), a distinct actor associated with ransomware activity.

The latest technical reporting on the new campaign is rich with detail, but at 4,200+ words, would take an estimated 40 minutes just to read. NARC AI quickly extracted all the relevant threat objects, TTPs, and relationships from the report for Tidal platform users to immediately operationalize.

**11/11/25: [Gootloader 2025 Resurgence Campaign](https://app.tidalcyber.com/campaigns/a2ce8adc-c565-4d47-b8d4-e3001b5d92c1?tab=2) – Spotlight Procedures**

- Gootloader specializes in evading detection, using at least five distinct methods of obfuscation alone. Defense-in-depth is important, and many of these actors’ post-compromise actions align with previously observed behavior, for example:
- **PS1031118: Perform Kerberoasting Attack via PowerShell** 
    - The adversary executes a lengthy PowerShell command to perform a Kerberoasting attack, extracting crackable password hashes for accounts with Service Principal Names.

> Threat-Led Defense commentary: Open-source detection rules like [this](https://app.tidalcyber.com/capability/dcb9836f-a44b-5548-a123-b1d8880eddc7) can be used to detect this adversary action by recognizing PowerShell scripts that have the capability of requesting kerberos tickets.

- **PS1031119: Remote Command Execution on Domain Controller via Impacket** 
    - The threat actor leveraged Impacket to remotely execute a command on the Domain Controller. The command wrapped by Impacket creates a temporary batch file (*execute.bat*) under *C:\Windows\TEMP\*, runs *vssadmin list shadows*, redirects output, and deletes the batch file.

> **Threat-Led Defense commentary**: Various broad or narrow defense approaches exist, including: monitor for the presence of suspicious files in %TEMP% (e.g., files named s01bafg or orl) that may contain encrypted backup C2 server IP addresses; monitor for the enumeration of Volume Shadow Copy snapshots (e.g., via *vssadmin list shadows*), which may indicate ransomware preparation; and monitor for the use of tools like Impacket for remote command execution, especially on Domain Controllers.

 

 

[View full post](https://www.tidalcyber.com/threat-updates/threat-intel-content-update-11/11/2025)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Tidal Cyber"
  },
  "dateModified" : "2025-11-11T17:06:02.630Z",
  "datePublished" : "2025-11-11T17:06:02Z",
  "headline" : "Threat Intel Content Update: 11/11/2025",
  "image" : {
    "@type" : "ImageObject",
    "height" : 1667,
    "url" : "https://21164103.fs1.hubspotusercontent-na1.net/hubfs/21164103/Threat%20Intel%2011.11.25.jpg",
    "width" : 3000
  },
  "mainEntityOfPage" : "https://www.tidalcyber.com/threat-updates/threat-intel-content-update-11/11/2025",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "Threat Intelligence Content Updates"
  }
}
```