China-linked hackers targeted Mongolian government using Slack, Discord for covert communications
ID: e805c118-aca0-59dd-abbb-c70e4ed92ea5
STIX ID: report--e805c118-aca0-59dd-abbb-c70e4ed92ea5
Feed Name: The Record from Recorded Future News
Threat Score
GopherWhisper, a previously undocumented China-aligned threat actor active since at least November 2023, targeted a Mongolian government institution using custom Go-based tooling (LaxGopher and related loaders/injectors/backdoors) and abused legitimate services (Discord, Slack, Microsoft 365 Outlook, File.io) for command-and-control and data exfiltration; roughly a dozen systems were compromised and researchers suspect additional victims.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
