Goopy is a Windows malware family associated with stealthy execution, persistence, host profiling, and data theft. It is notable for masquerading as a legitimate Google component and for abusing DLL side-loading with trusted applications from vendors including Google, Microsoft, and Kaspersky to execute malicious code while reducing suspicion. Reported tradecraft includes impersonation of a legitimate updater DLL, runtime self-decryption through a polymorphic decryptor, and use of legitimate software components to help blend into normal system activity.
On infected hosts, Goopy can establish persistence through scheduled tasks configured to recur hourly. It performs basic user discovery by enumerating the current username via Windows API calls, supporting victim identification and operational awareness. Goopy has also been documented exfiltrating documents and other data from compromised systems.
A distinctive feature of Goopy is its use of Microsoft Outlook as part of command-and-control and exfiltration operations. It can communicate through a Microsoft Outlook backdoor macro, exfiltrate data over that Outlook-based channel, and modify Outlook security settings to suppress macro warnings, indicating deliberate defense-evasion measures tied to its communications mechanism.
Overall, Goopy is best characterized as a Windows backdoor used for covert access and data theft, combining DLL side-loading, masquerading, scheduled-task persistence, user discovery, Outlook-based command and control, and exfiltration.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes malware and threat actors creating, modifying, or invoking Windows scheduled tasks via Task Scheduler or schtasks for persistence, execution, and lateral movement.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
"Sandworm Team used heavily obfuscated code with Industroyer in its Windows Notepad backdoor." / "Action RAT's commands, strings, and domains can be Base64 encoded within the payload." / "APT41 used VMProtected binaries in multiple intrusions."
actors used the following command to rename one of their tools to a benign file name: ren "%temp%\upload" audiodg.exe ... APT1 ... used ... AcroRD32.exe ... as a name for malware ... APT28 ... changed extensions on files containing exfiltrated data to make them appear benign ... APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update.
Bundlore 'can change browser security settings to enable extensions to be installed'; Goopy 'disable Microsoft Outlook's security policies to disable macro warnings'; NanHaiShu 'change Internet Explorer settings to reduce warnings about malware activity.'
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
Multiple malware families and threat groups are described as collecting the victim username or enumerating logged-on users (e.g., “can collect the username from the victim’s machine”, “enumerates the current user during the initial infection”, “enumerates logged-on users”).
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
ADVSTORESHELL exfiltrates data over the same channel used for C2.
Crutch can exfiltrate data over the primary C2 channel (Dropbox HTTP API)... ODAgent can use an attacker-controlled OneDrive account to receive C2 commands and to exfiltrate files... OilBooster can use an actor-controlled OneDrive account for C2 communication and exfiltration... ZIRCONIUM has exfiltrated files via the Dropbox API C2.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses a Microsoft Outlook backdoor macro to communicate with command-and-control infrastructure.
Backdoor that enumerates the infected system's username.
Malware that impersonates Google update components to blend in.
Malware that exfiltrates data over a Microsoft Outlook-based C2 channel.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.