Goopy

S0477

Malware.View on attack.mitre.org

About this malware

Goopy is a Windows backdoor and Trojan used by APT32 and shares several similarities to another backdoor used by the group (Denis). Goopy is named for its impersonation of the legitimate Google Updater executable.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1005
Data from Local System

Goopy has the ability to exfiltrate documents from infected systems.

T1027.001
Binary Padding

Goopy has had null characters padded in its malicious DLL payload.

T1027.016
Junk Code Insertion

Goopy's decrypter have been inflated with junk code in between legitimate API functions, and also included infinite loops to avoid analysis.

T1033
System Owner/User Discovery

Goopy has the ability to enumerate the infected system's user name.

T1036.005
Match Legitimate Resource Name or Location

Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe.

T1041
Exfiltration Over C2 Channel

Goopy has the ability to exfiltrate data over the Microsoft Outlook C2 channel.

T1053.005
Scheduled Task

Goopy has the ability to maintain persistence by creating scheduled tasks set to run every hour.

T1057
Process Discovery

Goopy has checked for the Google Updater process to ensure Goopy was loaded properly.

T1059.003
Windows Command Shell

Goopy has the ability to use cmd.exe to execute commands passed from an Outlook C2 channel.

T1059.005
Visual Basic

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.

T1070.008
Clear Mailbox Data

Goopy has the ability to delete emails used for C2 once the content has been copied.

T1071.001
Web Protocols

Goopy has the ability to communicate with its C2 over HTTP.

T1071.003
Mail Protocols

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.

T1071.004
DNS

Goopy has the ability to communicate with its C2 over DNS.

T1106
Native API

Goopy has the ability to enumerate the infected system's user name via GetUserNameW.

View all 18 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. Cybereason Cobalt Kitty 2017 Open source
    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.