apt
GopherWhisper: A burrow full of malware
High
Summary
ESET researchers have identified a new China-aligned Advanced Persistent Threat (APT) group, dubbed GopherWhisper, that targeted a Mongolian governmental entity. The group utilizes a diverse toolkit primarily built in Go, including custom backdoors like LaxGopher and RatGopher, and leverages common communication platforms such as Discord, Slack, and Microsoft 365 Outlook for command and control. Analysis of C&C traffic extracted from these platforms provided valuable insights into the group’s operations and post-compromise activities, revealing a China-aligned operation.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data