Check out the results from our first round of ATT&CK Evaluations at attackevals.mitre.org!

GLOOXMAIL

GLOOXMAIL is malware used by APT1 that mimics legitimate Jabber/XMPP traffic. [1]

ID: S0026
Aliases: GLOOXMAIL, Trojan.GTALK
Type: MALWARE
Platforms: Windows

Version: 1.0

Techniques Used

DomainIDNameUse
EnterpriseT1102Web ServiceGLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol.[1][2]

Groups

Groups that use this software:

APT1

References