GootLoader operators hijacked Google search rankings for legal-agreement phrases, luring law firm staff to fake forum "direct download" pages that delivered malicious JavaScript loaders, some of which escalated via Cobalt Strike into REvil ransomware attacks, a pattern CFC's Incident Response Team documented after seeing it hit multiple insured legal services firms.
Reviewed by the Social Engineering Examples team.
In 2021, CFC's Incident Response Team, the incident-response arm of UK-based cyber insurer/MGA CFC, issued a client advisory (published 2021-07-01, labeled on-page as Friday, July 2, 2021) warning that it had "recently seen several ransomware attacks on legal services firms" traced back to GootLoader malware. The attackers used SEO poisoning to push compromised, unrelated websites (CFC's illustrative example was a marketing company's site) to the top of Google search results for specific legal-agreement search phrases. Victims clicking through landed on a page disguised as a forum post that appeared to directly answer their query and offered a "direct download." The download was a ZIP file containing a JavaScript file named after the search term; executing it installed GootLoader, which could then pull down further tools, notably Cobalt Strike modules, to stage a ransomware attack, with CFC noting GootLoader's association with the REvil group in observed cases. CFC additionally found that some compromised sites distributing GootLoader were themselves law firm websites, meaning law firms visiting other (compromised) law firms' sites could become infected, a watering-hole dynamic layered on top of the SEO-poisoning lure. The broader GootLoader-against-legal-services campaign was independently tracked for years by other vendors: Sophos first published on the GootLoader delivery platform in March 2021; eSentire issued its own legal-sector advisory in January 2022 (after observing fresh incidents, the latest on January 6, 2022, and noting legal clients made up 70% of its 2021 GootLoader caseload); Mandiant's long-running tracking (through January 2023) attributed the malware and infrastructure exclusively to threat cluster UNC2565, active since January 2021; and Cybereason issued a global threat alert in February 2023 following a December 2022 investigation into a continuing GootLoader wave.
GootLoader's operators (tracked by Mandiant as UNC2565) used malicious SEO ("SEO poisoning") to force compromised WordPress and other third-party websites, including hacked law firm sites per CFC, to rank at or near the top of Google results for narrow, low-competition legal phrases, especially those containing the word "agreement" (e.g., "the Canadian inter-company arbitration agreement"). A visitor searching that exact phrase would see a result whose site had nothing to do with law (CFC's example was a marketing company's site) but whose page had been seeded with content matching the query. Clicking through landed the visitor on a page styled as a forum post that appeared to directly answer the question with a "direct download" link. That link served a ZIP archive containing a JavaScript (.js) file named after the search term, so it looked like the legal document/template the user wanted. Double-clicking the .js file executed it via Windows Script Host, installing GootLoader, which then could fetch further payloads, commonly Cobalt Strike modules, to stage a full ransomware intrusion. CFC and Sophos both tied the loader's downstream activity to REvil/Sodinokibi ransomware in observed cases. CFC's incident responders also documented a watering-hole variant of the same infrastructure: compromised law firm websites were themselves used to serve GootLoader to other law firms whose staff visited them, extending the campaign within the legal sector.
The lure was a Google search result for an exact, ordinary-sounding legal phrase (CFC's own example: "the Canadian inter-company arbitration agreement") that appeared to lead straight to the document being sought, via a forum post promising a "direct download." The tell: the top-ranking site's stated business (e.g., a marketing firm) had no plausible connection to legal documents; the page required a file download to reveal an "answer" rather than just displaying text; and the surrounding page copy was often grammatically awkward because it had been engineered/stuffed to match the search query rather than written naturally. These were three checks CFC explicitly told clients to run before trusting any such download.
CFC reported that its Incident Response Team had "recently seen several ransomware attacks on legal services firms" apparently caused by GootLoader, and separately observed law firm websites compromised and repurposed to distribute GootLoader to other visiting law firms (a watering-hole extension of the campaign). No specific victim names, ransom amounts, or recovery costs were disclosed in CFC's advisory. Industry-wide, the GootLoader legal-sector wave continued to be tracked for years afterward: eSentire issued its own legal-services advisory in January 2022 after observing fresh attacks (most recently January 6, 2022) and reported legal clients made up 70% of its 2021 GootLoader caseload; Mandiant continued tracking the same infrastructure (attributed to UNC2565) through at least January 2023; Cybereason issued a global threat alert in February 2023 after a December 2022 investigation into an active GootLoader wave.
This case is a clean, well-documented example of watering-hole/SEO-poisoning social engineering that exploits professional trust in search rankings rather than tricking a specific individual with a crafted message. It shows how attackers can weaponize an entire professional community's routine behavior (lawyers searching for standard agreement templates) by manipulating the search layer itself, and how a single compromised niche website can become reusable attack infrastructure against peers in the same industry (law firm to law firm). It also illustrates the classic loader-to-ransomware pipeline: a seemingly minor JS-file execution provided a foothold that, per CFC and Sophos, escalated via Cobalt Strike into full REvil ransomware intrusions, underscoring why an initial "just a file download" moment is actually the highest-leverage point to stop a ransomware kill chain.
CFC's advisory recommended: sense-checking downloads (does the site's topic actually match the search term; is a download required to get an "answer"; does the page read grammatically odd); keeping anti-virus/anti-malware auto-updating with regular scans; keeping OS and applications patched/auto-updated; deploying a secure web gateway to flag malicious sites; using application allow-listing/device management to block execution of untrusted executables and scripts; and user awareness training on this specific lure pattern. Broader industry advisories (Sophos, Mandiant, eSentire, Cybereason) additionally recommend blocking execution of JavaScript/WSH files downloaded from the browser, monitoring for anomalous wscript.exe/PowerShell activity, and EDR detection of Cobalt Strike beacon indicators as a second line of defense once initial execution occurs.
After going quiet on March 31, 2025 following a researcher's disruption campaign, Gootloader returned on November 5, 2025 with a…
eSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns:…
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…