logo

China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors

ID: eae98b3f-ee23-5127-8d69-5d36049e0c4a

STIX ID: report--eae98b3f-ee23-5127-8d69-5d36049e0c4a

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-04-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

ESET attributes a previously undocumented China-aligned APT dubbed GopherWhisper to targeted intrusions against Mongolian government entities, deploying a family of Go- and C++-based backdoors and loaders (e.g., LaxGopher, RatGopher, SSLORDoor) that abuse Slack, Discord, Outlook drafts, and file.io for command-and-control and exfiltration; telemetry shows ~12 infected systems and additional victims indicated by attacker-controlled C2 channels.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.