eSentire's Threat Response Unit blocked 10 separate attacks across six unnamed law firms in Jan-Feb 2023, foiling two parallel campaigns: SEO-poisoned fake "agreement" downloads delivering GootLoader, and a compromised Notary Public website serving a fake Chrome update to deliver SocGholish.
Reviewed by the Social Engineering Examples team.
Between January and February 2023, eSentire's Threat Response Unit (TRU) identified and blocked 10 separate cyberattacks against employees at six different, unnamed law firms. The activity came from two unrelated malware campaigns running concurrently: one delivering GootLoader via black-hat SEO poisoning of compromised WordPress sites carrying fake "legal agreement" content, and the other delivering SocGholish (FakeUpdates) via a watering-hole compromise of a Notary Public website in the Miami area that legal professionals commonly visited, which served a fake Chrome browser-update prompt. eSentire published its findings on February 28, 2023, noting that unlike prior GootLoader campaigns it had tracked (which led to SunCrypt/REvil ransomware or Cobalt Strike), the January-February 2023 law-firm-targeted GootLoader activity did not result in ransomware deployment, which TRU flagged as a possible shift toward espionage or data-exfiltration motives.
Two independent, technically distinct infection chains ran in parallel against the same target vertical (law firm employees). GootLoader chain: attackers used black-hat SEO poisoning to get legitimate but compromised WordPress sites (hacked without the site owners' knowledge) to rank highly for niche legal search terms such as "agreement," "contract," or "contract salary calculator," phrases with low SEO competition that let a single poisoned blog post climb into the top five search results. An employee searching for a template would click through to what looked like an online forum thread answering their exact question, which hosted a ZIP archive purporting to be the requested agreement or contract template. Inside the ZIP was a malicious JavaScript (.js) file; when the victim double-clicked it expecting a document, it silently executed GootLoader, which established persistence and (per eSentire's related case research) has been used to drop Cobalt Strike into memory and enable hands-on-keyboard access within roughly two hours in similar intrusions. SocGholish/FakeUpdates chain: attackers compromised a legitimate Notary Public website in the Miami area that legal professionals routinely visited for notarization needs, and injected code that displayed a convincing fake "Chrome browser update is required" overlay. A visitor who clicked to accept the update instead downloaded SocGholish, a JavaScript-based loader that (in the broader threat landscape) commonly stages Cobalt Strike and has been paired with ransomware such as LockBit in other incidents, though no such follow-on was reported in this eSentire case set.
The lure worked because it hijacked two forms of implicit trust legal professionals rely on daily: trust in search engine rankings (a top-five Google result for "contract salary calculator" or "agreement template" felt authoritative) and trust in a routine, already-bookmarked professional resource (a Notary Public site legal staff visited normally). The GootLoader "tell" was subtle: the destination page mimicked an online forum rather than a proper legal-document repository, and the "document" delivered was a .js script inside a ZIP rather than a .docx/.pdf. The SocGholish "tell" was that a genuine Chrome update never originates from a website's own content or overlay, since it comes from the browser itself (chrome://settings/help), but the fake prompt was styled convincingly enough to pass casual inspection, especially for non-technical legal staff.
All 10 attack attempts against the six law firms were detected and blocked by eSentire before completing their objective; eSentire reported no confirmed breach, data theft, or ransomware deployment tied to this specific incident set. eSentire's analysts noted that despite GootLoader's known capability (in 2022 and other campaigns) to lead to SunCrypt/REvil ransomware or Cobalt Strike, the January-February 2023 law-firm-targeted GootLoader activity notably did not deploy ransomware, which the TRU team assessed as a possible indicator the campaign had shifted toward espionage/data-exfiltration objectives rather than purely financially-motivated extortion.
This case is a clean, well-documented example of two of the most prevalent "living off the land"/social-engineering-adjacent delivery vectors, SEO poisoning and fake browser-update watering holes, being used together against a single high-value vertical (law firms handle sensitive client, M&A, and litigation data, making them attractive espionage and extortion targets). It illustrates that initial-access brokers don't need phishing emails at all: abusing search-engine trust and a routinely-visited legitimate third-party site was enough to reach the intended victims. It also demonstrates why "was this a legitimate browser update or search result" needs to be part of end-user security training for professional-services staff, and shows a security vendor's real detection-and-block outcome (rather than a breach post-mortem), useful for illustrating that these techniques are common enough to appear as routine SOC blocks across multiple same-industry clients in a two-month window.
eSentire's Threat Response Unit (TRU) and MDR/SOC detected and blocked all 10 attempts before execution completed, isolating hosts and blocklisting C2 infrastructure (per related Jan 12, 2023 GootLoader case study). General defenses that would mitigate this vector: web-filtering/DNS blocking of newly-registered or reputation-poor domains, blocking JavaScript (.js) execution via double-click from downloaded ZIP archives (associate .js with a text editor, not wscript/cscript), disabling or tightly controlling browser "update" prompts that originate from page content rather than the browser itself, EDR rules flagging wscript.exe/mshta.exe spawned from browser downloads, user training that legitimate browser updates never come from a website pop-up, and monitoring for anomalous outbound beaconing consistent with Cobalt Strike staging. Because GootLoader operators are known to also deliver ransomware (SunCrypt, REvil/Sodinokibi) and Cobalt Strike in other campaigns, rapid detection-to-containment (eSentire cited ~2 hours in a related case) was the decisive control here.
After going quiet on March 31, 2025 following a researcher's disruption campaign, Gootloader returned on November 5, 2025 with a…
A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into…
A revived Lampion banking-trojan campaign spoofed Portugal's tax authority site to trick victims into pasting a PowerShell command into the…