GopherWhisper
China-aligned APT (ESET assessment; specific Chinese state entity not publicly attributed) · Espionage / intelligence collection against Mongolian government targets
Tactics, Techniques & Procedures (TTPs)
- RatGopher: Go-based RAT storing C2 commands in Microsoft Outlook draft folders — reads commands, writes output to drafts, never sends email (traffic indistinguishable from Outlook sync)
- JabGopher: RAT using Slack and Discord as C2 channels — commands and responses via attacker-controlled workspace messages
- BoxOfFriends: file exfiltration tool uploading to file.io — traffic appears as legitimate cloud file sharing
- LaxGopher: lightweight Go-based dropper for secondary payload delivery
- SSLORDoor: HTTPS reverse shell for interactive operator access
- CompactGopher / FriendDelivery: additional modular staging tools in the implant ecosystem
- Entire C2 infrastructure routes through legitimate cloud services — network perimeter monitoring and domain reputation blocking are ineffective
Known Targets
Analyst Notes
Discovered by ESET January 2025, disclosed publicly April 2026. GopherWhisper's defining characteristic is exclusive use of legitimate cloud services as C2 — Microsoft 365 Outlook drafts, Slack, Discord, file.io — making network-level detection through perimeter monitoring or domain reputation blocking essentially impossible. All attacker traffic is structurally identical to legitimate employee use of these platforms. The modular Go-based implant ecosystem (seven documented components) allows selective deployment per phase, reducing total forensic footprint. Geographic focus on Mongolia aligns with PRC interest in Mongolian government decisions on natural resources, foreign policy, and relationships with Russia.
Also Known As