New GopherWhisper APT group abuses Outlook, Slack, Discord for comms
ID: a1ce113f-93b3-5795-aea9-9f3727f83f2c
STIX ID: report--a1ce113f-93b3-5795-aea9-9f3727f83f2c
Feed Name: Bleeping Computer
GopherWhisper, a suspected China-linked state-backed APT active since at least 2023, employs a Go-based toolset (LaxGopher, RatGopher, BoxOfFriends, CompactGopher, etc.), a C++ backdoor (SSLORDoor), injectors/loaders, and exfiltration to file.io while abusing legitimate services (Slack, Discord, Microsoft 365/Graph API) for C2 and data theft; ESET recovered thousands of C2 messages, identified victimization of a Mongolian government entity and dozens of other victims, and published IoCs to aid defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
