GRIDINSOFT HELP CENTER

Gootkit Malware: Credential Theft and Response

What it is

Gootkit is a banking trojan for Windows that targets sectors like finance, law, and healthcare. It steals logins, browser cookies, and payment data, and can pull in extra payloads to widen the breach.

How it gets in

  • Search poisoning - booby-trapped downloads from fake SEO results

  • Phishing - invoice or court notice lures with harmful attachments

  • Bundled installers - repacked software and fake updates

What you may notice

  • Banking or portal logins ask for unusual extra steps

  • Odd browser redirects or new extensions you did not add

  • New scheduled tasks or services - spikes in outbound traffic

Remove it now - quick steps

  1. Disconnect from the internet and avoid banking on the infected device.

  2. Run a full anti-malware scan, quarantine results, reboot, then scan again.

  3. From a clean device, change passwords and enable MFA for email, banking, and admin accounts.

  4. Check startup items, scheduled tasks, services, and extensions - remove unknowns.

  5. Call your bank to review transactions and set alerts.

Prevent it

  • Download software only from official sources - avoid repacks and cracks.

  • Keep Windows, browsers, and Office updated - block macros by default.

  • Use reputable EDR or anti-malware plus email and web filtering.

  • Train staff to verify money or account changes out of band.

  • Consider DNS filtering to block known malicious domains.

Look for the delivery chain and exposed accounts

Preserve the malicious page, download, process tree, persistence, and network destinations before cleanup. Search web-proxy, DNS, and endpoint logs for other users who reached the same source. Isolate affected hosts and scan for additional payloads or remote-access tools. From a clean device, reset browser, email, banking, and administrative credentials used during the infection window; revoke sessions and review recovery settings. Treat Gootkit as a possible banker Trojan incident, where deleting malware does not reverse credential theft or fraudulent activity that already occurred.

Helpful?

Glossary (0-9, A-Z)

Still can’t find an answer?

Send us a ticket and we will get back to you.

Submit a ticket