Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GopherWhisper

Also known as: APT34, Earth Preta, Stately Taurus, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, APT28, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, Earth Lusca, TAG-22, Aquatic Panda, Red Dev 10, ETHEREAL PANDA, Soft Cell, Alloy Taurus, Nascent Ursa, Nodaria, FROZENVISTA, Storm-0587, DEV-0587, Saint Bear, EMBER BEAR, Lorec Bear, Bleeding Bear, Cadet Blizzard, OPERATION HANGOVER, Donot Team, Orange Kala, Clean Ursa, Cloud Atlas, OXYGEN, G0100, ATK116, Blue Odin, APTC35, Desert Falcon, Arid Viper, Bearded Barbie, IMPERIAL KITTEN, DUSTYCAVE, Cuboid Sandstorm, CURIUM, Evasive Panda, BOHRIUM, DEV-0228, NIOBIUM, RENEGADE JACKAL, Scimitar

Description

GopherWhisper is a China‑aligned APT group first identified around 2015, with confirmed activity through at least 2023. The attackers employ a sophisticated blend of traditional spearphishing campaigns—targeting webmail accounts and leveraging social media such as LinkedIn—and supply‑chain compromise techniques, including SolarWinds-related vectors. Once inside an environment, GopherWhisper drops custom Go‑engineered backdoors that are obfuscated with DLL side‑loading (e.g., Whisper.dll, JabGopher) and maintained via raw OpenSSL sockets (SSLORDoor) on port 443. Their primary C2 channel is routed through legitimate enterprise messaging services—Discord, Slack—and Microsoft 365 Outlook, which helps them evade detection by blending command chatter with normal workplace traffic. Data exfiltration typically occurs to public cloud storage or file‑sharing services such as file.io, and in some cases the group leverages corporate Microsoft 365 accounts for staged data delivery. The payloads are also capable of keylogging, screenshot capturing, and file enumeration, while leveraging Azure AD credentials where available. Target selection focuses on government entities, NGOs, and critical infrastructures across Mongolia, Russia, Ukraine, Iraq, and other Central and East Asian jurisdictions. Their campaigns have been tied to high‑profile incidents such as the 2020 Vatican attack, reinforcing a clear espionage motive centered on financial gain through state or NGO data acquisition.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Education
Healthcare
Non profit
Energy
Critical infrastructure
Think tank
Media
Hospitality
Aerospace
Pharmaceutical
Maritime
Manufacturing
Legal services
Utilities
Nuclear
Aviation
Gaming
Entertainment
Chemical
Transportation
Retail
Mining
Construction
Ngo

Targeted Countries / Regions

Mongolia
CN
RU
UA
US
IR
IN
IL
AE
PL
KR
BY
PK
JP
VN
GB
TR
IT
TW
LB
KZ
FR
IQ
DE
SA
ES
CA
SG
RO
NG
KP
MX
BR

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

GopherWhisper is a China‑aligned advanced persistent threat that harnesses legitimate messaging platforms such as Discord, Slack, and Microsoft 365 to move laterally, execute payloads, and exfiltrate data covertly. Leveraging Go‑based backdoors (LaxGopher, RatGopher, CompactGopher) and DLL side‑loading techniques, the group targets government, NGO, and critical infrastructure stakeholders—particularly in Mongolia and Central Asia—for espionage objectives. Security teams should monitor traffic to these platforms, block anomalous command and control patterns, and enforce strict endpoint detection for custom backdoors.

Goals & Targeting

GopherWhisper’s strategic objectives are consistent with state-sponsored cyber espionage: to obtain politically and economically valuable information from government and critical infrastructure actors in targeted regions (Mongolia, Central Asia). By exfiltrating financial data and credentials they aim to monetize the stolen assets—often selling to third parties or using them for blackmail—while also supporting larger geopolitical operations. This focus on finance‑related sectors (banking, utilities, maritime) indicates a dual motive: direct revenue generation from compromised accounts and indirect support of nation‑state policy objectives through economic intelligence gathering.

Enhanced Description

Key Capabilities

  • C2 over legitimate messaging platforms (Discord, Slack, Microsoft 365)
  • Exfiltration via corporate cloud services and file.io
  • Deployment of Go‑based custom backdoors (LaxGopher, RatGopher, CompactGopher, Whisper.dll)
  • DLL side‑loading and injector/loaders for persistence
  • Spearphishing via email and social media to harvest webmail credentials
  • Keylogging, screenshotting, and file listing tools (e.g., Zebrocy)
  • Supply‑chain compromise via SolarWinds vectors
  • Leveraging DNS queries and proxy chains for lateral movement
  • Use of LinkedIn and other public platforms for initial access

MITRE ATT&CK Tactics

Initial Access
Credential Access
Command and Control
Exfiltration
Execution
Persistence
Defense Evasion
Discovery

ATT&CK Techniques

T1053.005
T1132.001
T1027.013
T1074.001
T1588.006
T1074.002
T1005
T1070.006
T1608.002
T1595.002
T1112
T1583.004
T1090.002
T1583.003
T1021.007
T1041
T1547.001
T1090.003
T1584.006
T1102.002
T1595.003
T1573.002
T1567.002
T1059.003
T1070.004
T1071.001
T1550.001
T1078.004
T1090.001
T1566
T1566.002
T1055.001
T1113
T1048
T1105
T1064

Software / Tooling

LaxGopher
RatGopher
CompactGopher
Whisper.dll
JabGopher
SSLORDoor
Zebrocy
CrimsonRAT
AndroRAT
SolarWinds
InvisiMole
CALENDAR

Campaigns & Victims

GopherWhisper operates with a measured tempo, often staggering payload deployments over weeks or months to avoid detection. Their hallmark is the integration of mainstream collaboration tools into their command and control architecture—an approach that has been observed in both the early 2016‑2017 campaigns and recent activities disclosed in 2023. Victims are predominantly state organisations and NGOs within Mongolia and adjoining Central Asian republics, with sporadic incursions into corporate sectors such as telecommunications, energy, and finance. The group frequently re‑uses the same delivery mechanisms (Slack bots, Azure AD credential theft) across campaigns while occasionally expanding to new vectors like Trojanized Android applications. Notable past operations include a 2020 attack on the Vatican’s email system via spearphishing, and an alleged SolarWinds-linked compromise targeting U.S. governmental agencies—highlighting their ability to pivot between covert espionage and supply‑chain sabotage for broader strategic goals.

IOC Patterns

  • Discord/Slack/Microsoft 365 traffic used as C2 channels
  • Phishing emails harvesting webmail credentials
  • Trojanized Android applications delivering backdoors
  • Custom shared‑malware loaders on Windows/Android
  • DLL side-loading (JabGopher, Whisper.dll)
  • Keylogging and screen capture activity
  • Exfiltration via cloud services or file.io
  • Suspicious DNS resolution patterns and proxy chains

Recommended Actions

  • Implement monitoring of outbound traffic to Discord, Slack, Microsoft 365, and other messaging platforms for anomalous command chatter
  • Enforce strict egress filtering on cloud storage endpoints to detect unauthorized data uploads
  • Deploy EDR solutions capable of detecting Go‑based binaries and DLL injection techniques used by LaxGopher/RatGopher
  • Block or quarantine suspicious backdoor executables such as Whisper.dll, SSLORDoor, CompactGopher, while tracking deployment persistence points like Registry Run Keys
  • Enhance email security with advanced phishing detection, multi‑factor authentication and regular user training focused on LinkedIn/WhatsApp spearphishing • Apply network segmentation to limit lateral movement through legitimate collaboration hubs
  • Inspect DNS logs for anomalous zone transfers or recursive queries that could indicate exfiltration loops
  • Implement least privilege principles across all cloud accounts, restricting API access needed for command and control
  • Conduct regular audits of third‑party software supply chains to detect SolarWinds‑style compromises
  • Deploy dedicated threat hunting procedures targeting DLL side‑loading and obscure process injection patterns

Suggested Tags

APT
China-aligned
Go-based malware
Spearphishing
Credential Theft
Exfiltration via Cloud
Government Targeting
Cyber Espionage
East/Southeast Asia focus
Vatican 2020 attack
Custom Loaders
Backdoor Deployment
Android Malware
Supply Chain Attacks
DNS Exfiltration
Mongolia
Central Asia

Confidence Assessment

The synthesis is built upon multiple independent reports and technical observations, giving a high confidence level for the core capabilities—such as messaging‑based C2, Go‑engineered backdoors, and targeted spearphishing campaigns. Nevertheless, gaps remain regarding precise chronological activity, exact attribution lineage (whether subsumed under APT34 or distinct), and completeness of the toolset beyond the publicly documented samples. Future intelligence gathering should focus on validating newer artifacts, confirming operational tactics in the post‑2023 period, and cross‑checking against other Chinese or Iran-aligned groups to refine attribution.

ATT&CK Techniques

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 4 SHA-1 Hash 6 Domain 9 IPv4 Address 1

References

  1. www.eset.com — Cited by web research for: APT34
  2. www.welivesecurity.com — Cited by web research for: T1588.006
  3. www.varutra.com — Cited by web research for: ClickFix
  4. securityaffairs.com — Cited by web research for: CVE-2026-58048
  5. www.welivesecurity.com — Cited by web research for: cmd.exe

Intel Summary

36

Techniques

51

Tools

10

Campaigns

38

IOCs

0

Observed Data

12

Tactics

Tags

APT
Backdoor / C2
Data Exfiltration
Government Targeting
China-aligned
Espionage
Central Asia
Go-based malware
Spearphishing
Credential Theft
Exfiltration via Cloud
Cyber Espionage
East/Southeast Asia focus
Vatican 2020 attack
Custom Loaders
Backdoor Deployment
Android Malware
Supply Chain Attacks
DNS Exfiltration
Mongolia

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.