Close Menu
    What's Hot

    Party Like a Swede! A Guide to Celebrating Midsummer.

    Trump-backed Iowa Senate candidate says Iran war could become ‘political liability’

    What to Watch in Tuesday’s Primary Elections in Iowa, Montana and Beyond

    Facebook X (Twitter) Instagram
    Trending
    • Party Like a Swede! A Guide to Celebrating Midsummer.
    • Trump-backed Iowa Senate candidate says Iran war could become ‘political liability’
    • What to Watch in Tuesday’s Primary Elections in Iowa, Montana and Beyond
    • U.S. Was Asked to Blacklist Colombian Cartel Gold. It Was Also Buying It.
    • Opinion | Ian Bremmer on the Risks America Poses to the World
    • The World Has Only Four Great Powers—and They Might Not Be Who You Think
    • What Ireland and Germany Can Teach Us About Birthright Citizenship
    • Meet the Accidental Editor in Chief of Muslim Media
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors

    adminBy adminApril 23, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananApr 23, 2026Threat Intelligence / Malware

    China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors

    Mongolian governmental institutions have emerged as the target of a previously undocumented China-aligned advanced persistent threat (APT) group tracked as GopherWhisper.

    “The group wields a wide array of tools mostly written in Go, using injectors and loaders to deploy and execute various backdoors in its arsenal,” Slovakian cybersecurity company ESET said in a report shared with The Hacker News. “GopherWhisper abuses legitimate services, notably Discord, Slack, Microsoft 365 Outlook, and file.io for command-and-control (C&C) communication and exfiltration.”

    The group was first discovered in January 2025 following the discovery of a never-before-seen backdoor codenamed LaxGopher on a system belonging to a Mongolian governmental entity. Also discovered as part of the threat actor’s arsenal are a number of other malware families, mostly developed using Golang to receive instructions from the C&C server, execute them, and send the results back.

    Cybersecurity

    Also used by the threat actor is a file collection tool to gather files of interest and exfiltrate them in compressed format to the file[.]io file sharing service and a C++ backdoor that offers remote control over compromised hosts.

    Telemetry data from ESET shows that about 12 systems associated with the Mongolian governmental institution were infected by the backdoors, with C&C traffic from the attacker-controlled Discord and Slack servers indicating dozens of other victims.

    Exactly how GopherWhisper obtains initial access to the target networks is currently not known. But a successful foothold is followed by attempts to deploy a wide range of tools and implants –

    • JabGopher, an injector that executes the LaxGopher (“whisper.dll”) backdoor.
    • LaxGopher, a Go-based backdoor that uses Slack for C2 to execute commands via “cmd.exe” and publish the results back to the Slack channel, as well as download additional malware.
    • CompactGopher, a Go-based file collection utility dropped by LaxGopher to filter files of interest by extensions (.doc, .docx, .jpg, .xls, .xlsx, .txt, .pdf, .ppt, and .pptx.), compress them into ZIP files, encrypt the archives using AES-CFB-128, and exfiltrate them to file[.]io.
    • RatGopher, a Go-based backdoor that uses a private Discord server to receive C&C messages, execute commands, and publish the results back to the configured Discord channel, as well as upload and download files from file[.]io.
    • SSLORDoor, a C++-based backdoor that uses OpenSSL BIO for communication via raw sockets on port 443 to enumerate drives, perform file operations, and run commands based on C&C input via “cmd.exe.”
    • FriendDelivery, a malicious DLL that serves as a loader and injector for BoxOfFriends.
    • BoxOfFriends, a Go-based backdoor that uses the Microsoft Graph API to craft draft emails for C2 using hard-coded credentials, with the earliest Outlook account created for this purpose (“barrantaya.1010@outlook[.]com”) created on July 11, 2024.

    “Timestamp inspection of the Slack and Discord messages showed us that the bulk of them were being sent during working hours, i.e., between 8 a.m. and 5 p.m., which aligns with China Standard Time,” ESET researcher Eric Howard said. “Furthermore, the locale for the configured user in Slack metadata was also set to this time zone. We therefore believe that GopherWhisper is a China-aligned group.”

    Backdoors ChinaLinked GopherWhisper government Infects Mongolian systems
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleIn the English Countryside, a Regency-Era Parsonage With a Walled Garden
    Next Article Musk pledges to fix 2019-2023 Teslas that can’t fully self drive
    admin
    • Website

    Related Posts

    Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

    June 2, 2026

    This AI weather startup is out-forecasting government agencies

    June 2, 2026

    Mette Frederiksen Forms New Government in Denmark

    June 1, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Party Like a Swede! A Guide to Celebrating Midsummer.

    Trump-backed Iowa Senate candidate says Iran war could become ‘political liability’

    What to Watch in Tuesday’s Primary Elections in Iowa, Montana and Beyond

    U.S. Was Asked to Blacklist Colombian Cartel Gold. It Was Also Buying It.

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by