GopherWhisper
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
GopherWhisper is a China-aligned advanced persistent threat (APT) group that emerged in at least November 2023, primarily focused on cyberespionage. The group's distinguishing characteristic is its extensive and calculated abuse of legitimate communication and file-sharing services, including Slack, Discord, Microsoft 365 Outlook, and file.io, for command and control (C2) operations and data exfiltration. This tactic allows GopherWhisper to blend malicious traffic with normal enterprise activity, complicating detection. ESET researchers uncovered GopherWhisper's activities in January 2025 after observing a backdoor deployment against a Mongolian governmental entity, leading to a detailed analysis of the group's custom, largely Go-based toolset. The group is assessed with high confidence to be of Chinese origin, evidenced by C2 traffic patterns aligning with China Standard Time working hours and the use of Chinese-configured virtual machines.
Sectores objetivo (SOCRadar)
Public Administration