Register to stream ATT&CKcon 2.0 October 29-30

GLOOXMAIL

GLOOXMAIL is malware used by APT1 that mimics legitimate Jabber/XMPP traffic. [1]

ID: S0026
Associated Software: Trojan.GTALK
Type: MALWARE
Platforms: Windows
Version: 1.0

Techniques Used

Domain ID Name Use
Enterprise T1102 Web Service GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol. [1] [2]

Groups That Use This Software

ID Name References
G0006 APT1 [1]

References