LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0477: Goopy

Goopy is a Windows backdoor and Trojan used by APT32 and shares several similarities to another backdoor used by the group (Denis). Goopy is named for its impersonation of the legitimate Google Updater executable.[1]

EnterpriseS0477MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

S0477: Goopy describes [Goopy](https://attack.mitre.org/software/S0477) is a Windows backdoor and Trojan used by [APT32](https://attack.mitre.org/groups/G0050) and shares several similarities to another backdoor used by the group ([Denis](https://attack.mitre.org/software/S0354)). [Goopy](https://attack.mitre.org/software/S0477) is named for its impersonation of the legitimate Google Updater executable.(Citation: Cybereason Cobalt Kitty 2017)

Executive priority

S0477: Goopy is an official MITRE ATT&CK software. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate S0477: Goopy by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (Windows), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata
  • Network, endpoint, and security-tool telemetry

Detection direction

  • Validate whether S0477: Goopy appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Goopy

Goopy is a Windows backdoor and Trojan used by APT32 and shares several similarities to another backdoor used by the group (Denis). Goopy is named for its impersonation of the legitimate Google Updater executable.[1]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

18 rows
DomainIDNameRelationship / procedure
EnterpriseT1071.004DNSSub-technique

Goopy has the ability to communicate with its C2 over DNS.[1]

EnterpriseT1059.005Visual BasicSub-technique

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.[1]

EnterpriseT1027.016Junk Code InsertionSub-technique

Goopy's decrypter have been inflated with junk code in between legitimate API functions, and also included infinite loops to avoid analysis.[1]

EnterpriseT1685Disable or Modify Tools

Goopy has the ability to disable Microsoft Outlook's security policies to disable macro warnings.[1]

EnterpriseT1059.003Windows Command ShellSub-technique

Goopy has the ability to use cmd.exe to execute commands passed from an Outlook C2 channel.[1]

EnterpriseT1033System Owner/User Discovery

Goopy has the ability to enumerate the infected system's user name.[1]

EnterpriseT1071.001Web ProtocolsSub-technique

Goopy has the ability to communicate with its C2 over HTTP.[1]

EnterpriseT1057Process Discovery

Goopy has checked for the Google Updater process to ensure Goopy was loaded properly.[1]

EnterpriseT1070.008Clear Mailbox DataSub-technique

Goopy has the ability to delete emails used for C2 once the content has been copied.[1]

EnterpriseT1005Data from Local System

Goopy has the ability to exfiltrate documents from infected systems.[1]

EnterpriseT1106Native API

Goopy has the ability to enumerate the infected system's user name via GetUserNameW.[1]

EnterpriseT1071.003Mail ProtocolsSub-technique

Goopy has the ability to use a Microsoft Outlook backdoor macro to communicate with its C2.[1]

EnterpriseT1140Deobfuscate/Decode Files or Information

Goopy has used a polymorphic decryptor to decrypt itself at runtime.[1]

EnterpriseT1574.001DLLSub-technique

Goopy has the ability to side-load malicious DLLs with legitimate applications from Kaspersky, Microsoft, and Google.[1]

EnterpriseT1041Exfiltration Over C2 Channel

Goopy has the ability to exfiltrate data over the Microsoft Outlook C2 channel.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Goopy has impersonated the legitimate goopdate.dll, which was dropped on the target system with a legitimate GoogleUpdate.exe.[1]

EnterpriseT1053.005Scheduled TaskSub-technique

Goopy has the ability to maintain persistence by creating scheduled tasks set to run every hour.[1]

EnterpriseT1027.001Binary PaddingSub-technique

Goopy has had null characters padded in its malicious DLL payload.[1]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0050: APT32

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.[1][2][3]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.1
Created
Modified
Raw hash
79483051a47b4d29...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.1Current bundle79483051a47b…
19.11.1Older bundle79483051a47b…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Cybereason Cobalt Kitty 2017

    Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.

    Open source URL
  2. [2]
    mitre-attackS0477
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.