Victims receive Gootkit itself or, in some cases, the REvil (Sodinokibi) ransomware. The initial loader is spread via hacked websites using an interesting search engine optimization (SEO) technique to customize a fake template that tries to trick users to download a file. The infection process starts once the victim executes a malicious script inside the zip archive they just downloaded. The obfuscation consists of three layers where one decodes content for the next. The first of several stages that leads to the execution of the final payload.”]