Uptime Hamster: 10d 12h 41mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza GopherWhisper

GopherWhisper

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Ver en IntelTracker → APTTrail →
GopherWhisper is a China-aligned advanced persistent threat (APT) group that emerged in at least November 2023, primarily focused on cyberespionage. The group's distinguishing characteristic is its extensive and calculated abuse of legitimate communication and file-sharing services, including Slack, Discord, Microsoft 365 Outlook, and file.io, for command and control (C2) operations and data exfiltration. This tactic allows GopherWhisper to blend malicious traffic with normal enterprise activity, complicating detection. ESET researchers uncovered GopherWhisper's activities in January 2025 after observing a backdoor deployment against a Mongolian governmental entity, leading to a detailed analysis of the group's custom, largely Go-based toolset. The group is assessed with high confidence to be of Chinese origin, evidenced by C2 traffic patterns aligning with China Standard Time working hours and the use of Chinese-configured virtual machines.
Tipo
apt
Pais origen
CN
Motivacion
-
Impacto
7
Actualizado
Sat, 02 Ma

Sectores objetivo (SOCRadar)

Public Administration