Goopy — Malware Profile
Goopy is a Windows backdoor and Trojan used by APT32 and shares several similarities to another backdoor used by the group (Denis). Goopy is named for its impersonation of the legitimate Google Updater executable.
MITRE ATT&CK techniques (18)
- T1005 Data from Local System
- T1027.001 Binary Padding
- T1027.016 Junk Code Insertion
- T1033 System Owner/User Discovery
- T1036.005 Match Legitimate Resource Name or Location
- T1041 Exfiltration Over C2 Channel
- T1053.005 Scheduled Task
- T1057 Process Discovery
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1070.008 Clear Mailbox Data
- T1071.001 Web Protocols
- T1071.003 Mail Protocols
- T1071.004 DNS
- T1106 Native API
- T1140 Deobfuscate/Decode Files or Information
- T1574.001 DLL
- T1685 Disable or Modify Tools