Also known as: APT34, Earth Preta, Stately Taurus, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, APT28, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, Earth Lusca, TAG-22, Aquatic Panda, Red Dev 10, ETHEREAL PANDA, Soft Cell, Alloy Taurus, Nascent Ursa, Nodaria, FROZENVISTA, Storm-0587, DEV-0587, Saint Bear, EMBER BEAR, Lorec Bear, Bleeding Bear, Cadet Blizzard, OPERATION HANGOVER, Donot Team, Orange Kala, Clean Ursa, Cloud Atlas, OXYGEN, G0100, ATK116, Blue Odin, APTC35, Desert Falcon, Arid Viper, Bearded Barbie, IMPERIAL KITTEN, DUSTYCAVE, Cuboid Sandstorm, CURIUM, Evasive Panda, BOHRIUM, DEV-0228, NIOBIUM, RENEGADE JACKAL, Scimitar
GopherWhisper is a China‑aligned APT group first identified around 2015, with confirmed activity through at least 2023. The attackers employ a sophisticated blend of traditional spearphishing campaigns—targeting webmail accounts and leveraging social media such as LinkedIn—and supply‑chain compromise techniques, including SolarWinds-related vectors. Once inside an environment, GopherWhisper drops custom Go‑engineered backdoors that are obfuscated with DLL side‑loading (e.g., Whisper.dll, JabGopher) and maintained via raw OpenSSL sockets (SSLORDoor) on port 443. Their primary C2 channel is routed through legitimate enterprise messaging services—Discord, Slack—and Microsoft 365 Outlook, which helps them evade detection by blending command chatter with normal workplace traffic. Data exfiltration typically occurs to public cloud storage or file‑sharing services such as file.io, and in some cases the group leverages corporate Microsoft 365 accounts for staged data delivery. The payloads are also capable of keylogging, screenshot capturing, and file enumeration, while leveraging Azure AD credentials where available. Target selection focuses on government entities, NGOs, and critical infrastructures across Mongolia, Russia, Ukraine, Iraq, and other Central and East Asian jurisdictions. Their campaigns have been tied to high‑profile incidents such as the 2020 Vatican attack, reinforcing a clear espionage motive centered on financial gain through state or NGO data acquisition.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GopherWhisper is a China‑aligned advanced persistent threat that harnesses legitimate messaging platforms such as Discord, Slack, and Microsoft 365 to move laterally, execute payloads, and exfiltrate data covertly. Leveraging Go‑based backdoors (LaxGopher, RatGopher, CompactGopher) and DLL side‑loading techniques, the group targets government, NGO, and critical infrastructure stakeholders—particularly in Mongolia and Central Asia—for espionage objectives. Security teams should monitor traffic to these platforms, block anomalous command and control patterns, and enforce strict endpoint detection for custom backdoors.
Goals & Targeting
GopherWhisper’s strategic objectives are consistent with state-sponsored cyber espionage: to obtain politically and economically valuable information from government and critical infrastructure actors in targeted regions (Mongolia, Central Asia). By exfiltrating financial data and credentials they aim to monetize the stolen assets—often selling to third parties or using them for blackmail—while also supporting larger geopolitical operations. This focus on finance‑related sectors (banking, utilities, maritime) indicates a dual motive: direct revenue generation from compromised accounts and indirect support of nation‑state policy objectives through economic intelligence gathering.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GopherWhisper operates with a measured tempo, often staggering payload deployments over weeks or months to avoid detection. Their hallmark is the integration of mainstream collaboration tools into their command and control architecture—an approach that has been observed in both the early 2016‑2017 campaigns and recent activities disclosed in 2023. Victims are predominantly state organisations and NGOs within Mongolia and adjoining Central Asian republics, with sporadic incursions into corporate sectors such as telecommunications, energy, and finance. The group frequently re‑uses the same delivery mechanisms (Slack bots, Azure AD credential theft) across campaigns while occasionally expanding to new vectors like Trojanized Android applications. Notable past operations include a 2020 attack on the Vatican’s email system via spearphishing, and an alleged SolarWinds-linked compromise targeting U.S. governmental agencies—highlighting their ability to pivot between covert espionage and supply‑chain sabotage for broader strategic goals.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The synthesis is built upon multiple independent reports and technical observations, giving a high confidence level for the core capabilities—such as messaging‑based C2, Go‑engineered backdoors, and targeted spearphishing campaigns. Nevertheless, gaps remain regarding precise chronological activity, exact attribution lineage (whether subsumed under APT34 or distinct), and completeness of the toolset beyond the publicly documented samples. Future intelligence gathering should focus on validating newer artifacts, confirming operational tactics in the post‑2023 period, and cross‑checking against other Chinese or Iran-aligned groups to refine attribution.
Satellite Turla
Epic Turla
The 'Penquin' Turla
Witchcoven
RUAG hack
Mosquito
Moonlight Maze
Red October
Cloud Atlas
Lucky Elephant
No observed data linked yet.
36
Techniques
51
Tools
10
Campaigns
38
IOCs
0
Observed Data
12
Tactics