GLOOXMAIL

GLOOXMAIL is malware used by APT1 that mimics legitimate Jabber/XMPP traffic. [1]

ID: S0026
Associated Software: Trojan.GTALK
Type: MALWARE
Platforms: Windows
Version: 1.2
Created: 31 May 2017
Last Modified: 28 August 2024

Techniques Used

Domain ID Name Use
Enterprise T1071 .005 Application Layer Protocol: Publish/Subscribe Protocols

GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol for C2.[2]

Enterprise T1102 .002 Web Service: Bidirectional Communication

GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol.[1][3]

Groups That Use This Software

ID Name References
G0006 APT1

[1]

References