GLOOXMAIL

S0026

Malware.View on attack.mitre.org

About this malware

GLOOXMAIL is malware used by APT1 that mimics legitimate Jabber/XMPP traffic.

Techniques used2

Procedure examples2

TechniqueProcedure example
T1071.005
Publish/Subscribe Protocols

GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol for C2.

T1102.002
Bidirectional Communication

GLOOXMAIL communicates to servers operated by Google using the Jabber/XMPP protocol.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Mandiant APT1 Open source
    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.