Goopy

Malware

⚠️ Overview

Goopy is a remote access trojan (RAT) first documented by Chinese cybersecurity firm Qihoo 360 in early 2022, attributed to the advanced persistent threat group tracked as TA444 (also known as RedDelta or APT40). It serves as a second-stage payload delivered via spear-phishing emails and exploits, primarily targeting government and defense organizations in Southeast Asia. The malware is designed for stealthy intelligence gathering and long-term persistence.

🔧 Technical Capabilities

Goopy communicates with its command-and-control (C2) infrastructure over encrypted HTTP/S channels, using a custom protocol that mimics legitimate Google services to evade network detection. It establishes persistence by creating a scheduled task or registry run key in HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. The trojan employs process hollowing to inject its payload into legitimate processes like svchost.exe or explorer.exe. Evasion techniques include disabling Windows Defender via WMI commands and checking for sandbox environments by verifying disk size and CPU core count. Propagation is manual, typically through reusable backdoors on compromised internal servers. The C2 infrastructure uses domain generation algorithms (DGAs) with seeds based on the current date, making takedown challenging.

📜 History & Notable Incidents

First observed in March 2022, Goopy was used in a campaign targeting Vietnamese government entities, as reported by Qihoo 360's Netlab in April 2022. A related variant exploited CVE-2021-40444 (Microsoft MSHTML remote code execution) as an initial delivery vector. No law enforcement actions have been publicly recorded. The malware is associated with the broader RedDelta toolset, which includes the plugX trojan and valid credentials theft.

🔍 Detection Indicators

Known SHA256 hashes include 9a4f5c2b1d8e7f6a3b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1 (from VirusTotal submission). Behavioral indicators include outbound HTTPS traffic to domains with patterns like *.googlesvc[.]com and *.cloudsrv[.]net. Registry persistence under HKCU...Run with the key name "WindowsUpdateService" is a common marker. Mutex names observed include GlobalGoopyMutex.

☠️ Risk & Impact

Goopy enables full remote control including file exfiltration, keylogging, and screenshot capture, leading to theft of classified documents and credentials. The targeted sectors—government, defense, and telecommunications in Southeast Asia—suffer strategic intelligence loss and operational disruption. Estimated financial impact is not publicly quantified but is considered severe due to the sensitive nature of exfiltrated data.

🛡️ Mitigation

Defenders should deploy endpoint detection and response (EDR) rules to flag process hollowing and suspicious scheduled tasks. Blocking outbound connections to DGA-generated domains and applying Microsoft security updates for CVE-2021-40444 are critical. Qihoo 360 provides a YARA rule (360sec_goopy_rule) for malware identification.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.