logo

GopherWhisper: A burrow full of malware

ID: 886ae3f0-1a3a-570f-ab53-eaa2d6f0a9ae

STIX ID: report--886ae3f0-1a3a-570f-ab53-eaa2d6f0a9ae

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
85/100

Date Published: 2026-04-23

Date Updated: 2026-05-01

...
...

ESET Research identified a previously undocumented China-aligned APT group, GopherWhisper, which targeted a Mongolian government entity using a diverse toolset of Go-based backdoors (LaxGopher, RatGopher, BoxOfFriends), injectors/loaders (JabGopher, FriendDelivery), an exfiltration tool (CompactGopher), and a C++ backdoor (SSLORDoor); the group abused Slack, Discord, Microsoft 365 Outlook, and file.io for C2 and exfiltration, and recovered C&C messages and draft emails that revealed operator activity, timezones consistent with UTC+8, and other operational details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.