GopherWhisper: new China-linked APT targets Mongolia with Go-based malware
ID: c0bbca74-4eec-525a-87c6-f749a3b34da2
STIX ID: report--c0bbca74-4eec-525a-87c6-f749a3b34da2
Feed Name: Security Affairs
Threat Score
ESET uncovered a previously undocumented China-aligned APT dubbed GopherWhisper targeting a Mongolian government entity with a suite of mostly Go-based loaders, injectors, and backdoors. The group abused legitimate platforms (Slack, Discord, Outlook, file.io) for C2 and exfiltration; researchers extracted thousands of attacker messages and confirmed about 12 infected systems while observing operational patterns consistent with Chinese working hours.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
