Data Security, Malware, Threat Intelligence

GopherWhisper: China-linked hackers target governments with custom Go toolkit

China Bans Cyber Attacks: Examining Internet Security with Chinese Flag and Binary Data Through a Magnifying Glass Concept

Bleeping Computer reports that a sophisticated state-backed threat actor, identified as GopherWhisper, has been actively targeting government entities since at least 2023. This group, believed to be linked to China, employs a custom toolkit written in the Go programming language and utilizes legitimate services for its malicious operations.

ESET research revealed GopherWhisper's tactics, which include deploying multiple Go-based backdoors like LaxGopher and RatGopher, along with a C++ backdoor named SSLORDoor. These tools leverage popular platforms such as Microsoft 365 Outlook, Slack, and Discord for command-and-control (C2) communication. The attackers also utilize a custom tool, CompactGopher, to compress and exfiltrate stolen data to file-sharing services like File.io. In one identified campaign, a Mongolian government entity was targeted, with dozens of other victims suspected based on C2 traffic analysis.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds