Previously limited to initial access brokering, the Gootloader group has pivoted to a nasty post-compromise "GootBot" attack, each implant with its own C2.
Source: DarkReading
Source Link: https://www.darkreading.com/attacks-breaches/gootloader-malicious-custom-bot-army-enterprise-networks