Chinese APT Abuses Multiple Cloud Tools to Spy on Mongolia
ID: 501b9bfe-68f5-5802-8c86-41c31a6b7f3d
STIX ID: report--501b9bfe-68f5-5802-8c86-41c31a6b7f3d
Feed Name: Dark Reading
Threat Score
GopherWhisper, a Chinese-aligned APT active since November 2023, targeted Mongolian government networks using multiple custom backdoors that abuse mainstream cloud services (Slack, Discord, Outlook drafts, file.io) for C2 and exfiltration; ESET identified at least 12 infected systems in one government institution and evidence of broader impact, noting the group's high rate of tool development but relatively modest sophistication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
