Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

New East African bat coronavirus can invade human cells

Addressing the flexible plastic waste challenge

China-linked GopherWhisper infects 12 Mongolian government systems with Go backdoor

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » China-linked GopherWhisper infects 12 Mongolian government systems with Go backdoor
Identity

China-linked GopherWhisper infects 12 Mongolian government systems with Go backdoor

By April 23, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananApril 23, 2026Threat Intelligence/Malware

Mongolian government agencies have emerged as targets of a previously undocumented China-aligned Advanced Persistent Threat (APT) group tracked as GopherWhisper.

“The group leverages a wide range of tools, primarily written in Go, and uses injectors and loaders to deploy and execute various backdoors in its arsenal,” Slovak cybersecurity firm ESET said in a report shared with The Hacker News. “GopherWhisper exploits legitimate services, particularly Discord, Slack, Microsoft 365 Outlook, and file.io, for command and control (C&C) communications and theft.”

The group was first discovered in January 2025 following the discovery of an unprecedented backdoor codenamed LaxGopher on systems belonging to a Mongolian government agency. Many other malware families have also been discovered as part of threat actors’ arsenals. These malware families are primarily developed using Golang to receive instructions from a C&C server, execute them, and send results back.

Threat actors also use file harvesting tools that collect files of interest and extract them into files in a compressed format.[.]io A C++ backdoor that provides file sharing services and remote control of compromised hosts.

ESET telemetry data indicates that around a dozen systems associated with Mongolian government agencies were infected with the backdoor, and there are dozens of other victims with C&C traffic from attacker-controlled Discord and Slack servers.

It is currently unclear exactly how GopherWhisper gains initial access to the target network. However, successful scaffolds are followed by attempts to introduce different tools and implants.

JabGopher, an injector that runs the LaxGopher (‘whisper.dll’) backdoor. LaxGopher is a Go-based backdoor that uses Slack for C2 to execute commands via “cmd.exe”, publish results to a Slack channel, and download additional malware. CompactGopher is a Go-based file collection utility dropped by LaxGopher that filters the files of interest by extension (.doc, .docx, .jpg, .xls, .xlsx, .txt, .pdf, .ppt, and .pptx), compresses them into ZIP files, encrypts the archive using AES-CFB-128, and extracts it to a file.[.]Io. RatGopher is a Go-based backdoor that uses a private Discord server to receive C&C messages, execute commands, publish results to configured Discord channels, and upload and download files from files.[.]Io. SSLORDoor is a C++-based backdoor that uses OpenSSL BIO for communication over raw sockets on port 443 to enumerate drives, perform file operations, and execute commands based on C&C input via ‘cmd.exe’. FriendDeliver is a malicious DLL that acts as a loader and injector for BoxOfFriends. BoxOfFriends is a Go-based backdoor that uses the Microsoft Graph API to create draft emails for C2 with hard-coded credentials, and the oldest Outlook account created for this purpose (‘barrantaya.1010@outlook’)[.]com”) Created on July 11, 2024.

“When we examined timestamps on Slack and Discord messages, we found that the majority of messages were sent during business hours, between 8am and 5pm, coinciding with China Standard Time,” ESET researcher Eric Howard said. “Additionally, the user’s locale set in Slack metadata was also set to this time zone. Therefore, GopherWhisper appears to be a pro-China group.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleVercel finds more compromised accounts in breach related to Context.ai
Next Article Addressing the flexible plastic waste challenge

Related Posts

Vercel finds more compromised accounts in breach related to Context.ai

April 23, 2026

Apple patches iOS flaw that saved Signal notifications deleted in FBI investigation

April 23, 2026

Malicious KICS Docker image and VS Code extension impact Checkmarx supply chain

April 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

New East African bat coronavirus can invade human cells

Addressing the flexible plastic waste challenge

China-linked GopherWhisper infects 12 Mongolian government systems with Go backdoor

Vercel finds more compromised accounts in breach related to Context.ai

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.