news.mlab.sh
Back to the feed
apt

GopherWhisper: A burrow full of malware

High
Summary

ESET researchers have identified a new China-aligned Advanced Persistent Threat (APT) group, dubbed GopherWhisper, that targeted a Mongolian governmental entity. The group utilizes a diverse toolkit primarily built in Go, including custom backdoors like LaxGopher and RatGopher, and leverages common communication platforms such as Discord, Slack, and Microsoft 365 Outlook for command and control. Analysis of C&C traffic extracted from these platforms provided valuable insights into the group’s operations and post-compromise activities, revealing a China-aligned operation.

Read the full article at WeLiveSecurity

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.