GopherWhisper is a China-aligned APT targeting Mongolian government entities and active in Central Asia.
Analyst brief
GopherWhisper is a China-aligned APT of unknown type that has targeted Mongolian government entities and is assessed to have additional victims in Central Asia. Its key TTPs include routing C2 traffic through legitimate platforms like Slack, Discord, and Microsoft 365 Outlook, alongside using custom tools such as LaxGopher, RatGopher, CompactGopher, JabGopher (for DLL side-loading), and the SSLORDoor backdoor. Defenders should monitor for anomalous network traffic to these legitimate services and scrutinize unusual DLL loading behaviors.
GopherWhisper
unknown
GopherWhisper is a China-aligned APT that routes C2 traffic through legitimate enterprise platforms like Slack, Discord, and Microsoft 365 Outlook to evade detection. Its toolkit includes the LaxGopher backdoor for Slack, RatGopher for Discord, and CompactGopher for data exfiltration via file.io. The group employs DLL side-loading via JabGopher and uses raw OpenSSL socket C2 on port 443 with the SSLORDoor backdoor. GopherWhisper has targeted Mongolian government entities and is assessed to have additional unidentified victims in Central Asia.