logo

GopherWhisper: new China-linked APT targets Mongolia with Go-based malware

ID: c0bbca74-4eec-525a-87c6-f749a3b34da2

STIX ID: report--c0bbca74-4eec-525a-87c6-f749a3b34da2

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-04-26

Date Updated: 2026-05-05

Author: Pierluigi Paganini

...
...

ESET uncovered a previously undocumented China-aligned APT dubbed GopherWhisper targeting a Mongolian government entity with a suite of mostly Go-based loaders, injectors, and backdoors. The group abused legitimate platforms (Slack, Discord, Outlook, file.io) for C2 and exfiltration; researchers extracted thousands of attacker messages and confirmed about 12 infected systems while observing operational patterns consistent with Chinese working hours.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.