China-Linked APT GopherWhisper Exploits Legitimate Services in Cyber Attacks on Government Entities
A newly identified advanced persistent threat (APT) group, dubbed GopherWhisper, has been linked to cyber attacks on government entities, utilizing legitimate services for command-and-control (C&C) communication and data exfiltration. According to ESET, the group, operating out of China since at least November 2023, employs multiple Go-based backdoors and custom loaders. The investigation revealed that GopherWhisper targeted a Mongolian governmental organization, infecting approximately 12 systems. The group uses tools like LaxGopher, which communicates via Slack, and RatGopher, which uses Discord, to execute commands and exfiltrate data.