logo

Chinese APT Abuses Multiple Cloud Tools to Spy on Mongolia

ID: 501b9bfe-68f5-5802-8c86-41c31a6b7f3d

STIX ID: report--501b9bfe-68f5-5802-8c86-41c31a6b7f3d

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-04-24

Date Updated: 2026-04-23

Author: Nate Nelson

...
...

GopherWhisper, a Chinese-aligned APT active since November 2023, targeted Mongolian government networks using multiple custom backdoors that abuse mainstream cloud services (Slack, Discord, Outlook drafts, file.io) for C2 and exfiltration; ESET identified at least 12 infected systems in one government institution and evidence of broader impact, noting the group's high rate of tool development but relatively modest sophistication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.