Goopy

MITRE ATT&CK: S0477 View on attack.mitre.org

Aliases: Goopy

First seen
2019-04-01 00:00:00
Malware type
backdoor, trojan
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:31:34

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:vn country_code:kh

Context

Goopy is a Windows backdoor and Trojan used by APT32 and shares several similarities to another backdoor used by the group (Denis). Goopy is named for its impersonation of the legitimate Google Updater executable.

Detection coverage

  • 448 Sigma rules

Malware & tools used

  • Visual Basic (attack-pattern)
  • Junk Code Insertion (attack-pattern)
  • Disable or Modify Tools (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Web Protocols (attack-pattern)
  • Process Discovery (attack-pattern)
  • Clear Mailbox Data (attack-pattern)
  • Data from Local System (attack-pattern)
  • Native API (attack-pattern)
  • Mail Protocols (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • DLL (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Binary Padding (attack-pattern)
  • DNS (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S0477 (report)
  • cdn2.hubspot.net — Cybereason%20Labs%20Analysis%20Operation%20Cobalt%20Kitty (report)

External references