Goopy
MITRE ATT&CK: S0477 View on attack.mitre.org
Aliases: Goopy
- First seen
- 2019-04-01 00:00:00
- Malware type
- backdoor, trojan
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:31:34
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:vn country_code:kh
Context
Goopy is a Windows backdoor and Trojan used by APT32 and shares several similarities to another backdoor used by the group (Denis). Goopy is named for its impersonation of the legitimate Google Updater executable.
Detection coverage
- 448 Sigma rules
Malware & tools used
- Visual Basic (attack-pattern)
- Junk Code Insertion (attack-pattern)
- Disable or Modify Tools (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Web Protocols (attack-pattern)
- Process Discovery (attack-pattern)
- Clear Mailbox Data (attack-pattern)
- Data from Local System (attack-pattern)
- Native API (attack-pattern)
- Mail Protocols (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- DLL (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Scheduled Task (attack-pattern)
- Binary Padding (attack-pattern)
- DNS (attack-pattern)
Used by threat actors
- APT32 (threat-actor)
Reports & references
- MITRE ATT&CK — S0477 (report)
- cdn2.hubspot.net — Cybereason%20Labs%20Analysis%20Operation%20Cobalt%20Kitty (report)