logo

New GopherWhisper APT group abuses Outlook, Slack, Discord for comms

ID: a1ce113f-93b3-5795-aea9-9f3727f83f2c

STIX ID: report--a1ce113f-93b3-5795-aea9-9f3727f83f2c

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Bill Toulas

...
...

GopherWhisper, a suspected China-linked state-backed APT active since at least 2023, employs a Go-based toolset (LaxGopher, RatGopher, BoxOfFriends, CompactGopher, etc.), a C++ backdoor (SSLORDoor), injectors/loaders, and exfiltration to file.io while abusing legitimate services (Slack, Discord, Microsoft 365/Graph API) for C2 and data theft; ESET recovered thousands of C2 messages, identified victimization of a Mongolian government entity and dozens of other victims, and published IoCs to aid defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.