Security researcher dedicated to pissing off the Gootloader Threat Actor.

Joined April 2023
44 Photos and videos
Gootloader retweeted
21 Jul 2025
1
1
24
2,138
Gootloader retweeted
🚨 Trojanized CPU-Z → STXRAT → PureLogs Stealer → PureHVNC → 54hrs of exfil through a hidden QEMU VM. We caught everything after. First documented full post-exploitation chain for this campaign. IOCs & hunting artifacts link in thread #ThreatIntel #DFIR #Malware
3
22
97
7,752
Gootloader retweeted
Before I was arrested in 2009, I was at the height of my little cybercriminal "empire". I was standing at a crossroads. Part of me wanted an exit and a chance to redirect my skills toward something constructive. Another part of me feared that if I walked away, all the risks I had taken as a hacker would have meant nothing. 11 years in prison for hacking taught me that the reputation I thought I had built in that world, the ideals I believed in, and the status I thought mattered turned out to be far more futile than I could have imagined at the time. When everything collapsed, I realized that none of that mattered. I learned that most of what passes for loyalty and respect in cybercrime is conditional. Today, there's no reason to turn to cybercrime in order to feel accepted or to enjoy camaraderie and acceptance among peers, or to pursue a sense of justice and vindication. Cybercrime isn't the solution, or the stepping stone. All the hackers in my crew from back in the day have respectable cybersecurity careers today,Ā because sooner or later everyone learns the same lesson. Cybercrime has limits, and it does not put food on the table without tremendous risk. #realtalk #hacking #hacktivism #truecrime
6
16
135
25,914
Anyone have a good way to monitor new @GoogleAds for a specific domain?
2
1
2
536
Nice write up. #gootloader is known to push Oyster
#OysterLoader (aka #Broomstick or #Cleanup) is not just another downloader. Often serving as a precursor to #Rhysida #ransomware campaigns or distributing commodity malware such as #Vidar, this threat has evolved significantly as we enter 2026. buff.ly/ZAQuErp #Reverse
1
11
685
This was a fun one to dig into Confirmed exploitation requires: • User registration enabled • LA-Studio Element Kit = 1.5.6.3 • At least one published Elementor page PoC confirmed (details withheld). Nice find by Jitlada. Boeing777 & Waris Damkham!
1
3
524
#CVE-2026-0920
177
Gootloader retweeted
āš ļø GootLoader now uses 500–1,000 ZIP files glued together! The broken ZIP won’t open in WinRAR or 7-Zip, but Windows Explorer still opens it and runs the JavaScript malware. Each download is different, so file hashes don’t match. šŸ”— Learn how this ZIP trick bypasses defenses → thehackernews.com/2026/01/go…
5
37
120
13,825
Great write-up on the #gootloader zip! Hopefully with these details @MicrosoftSec will take this seriously and fix their ZIP unarchiver. Great Yara rule. #100daysofyara
Gootloader malware returned in November after a hiatus. They work with Vanilla Tempest (currently using Rhysida ransomware). We took a deep look at their first-stage delivery mechanism—a deliberately broken ZIP archive designed to bypass detection. (1/12)
4
41
5,293
I feel this was a major success! Thanks all
1
6
211
@gnamedotcom @dowomain @brandomainable please act on the domains reported case GW2026010920446794. My reputation, plus what I provided on Friday, should be enough to stop protecting a criminal's infrastructure
1
1
113
Gootloader retweeted
Right before the holidays, I broke the news that DHS had effectively forced out the staffer running CISA's ransomware warning program: cybersecuritydive.com/news/c… People who worked w/ him are really worried. And we may be starting to see the impact... linkedin.com/feed/update/urn…
8
306
718
47,530
New Year’s wish: #Gootloader hangs up the keyboard so we can all stop running this endless game of cyber cat and mouse. Let the mouse rest. Let the cat rest. Let me rest.
1
10
1,450
Gootloader retweeted
You may not know Dave Stern, but you should. The Pre-Ransomware Notification Initiative (PRNI) effort by CISA prevented an estimated $9 billion in damages by working with industry to notify companies of ransomware attacks before attackers lock systems. It is disheartening to see Dave leave CISA, but this is an incredible legacy to leave behind and a model we should look to replicate in the future. cybersecuritydive.com/news/c…
8
39
161
19,273
Gootloader retweeted
CertCentral is now TheCertGraveyard[.]org & CertGraveyard[.]org. The CertCentral API returns an error directing to use the new domains. Please give me a like or a share to get the word out. Also use the site to report and investigate certificates used to sign malware. :)
I'm being required to give up the domain CertCentral[.]org; and the change has to happen by Monday. I'm noodling on alternative names. Keep an eye out for the change.
5
47
78
19,785
Don’t know why everyone is worrying about RAM prices. You can just @DownloadMoreRam for free
1
316