{"id":235059,"date":"2026-04-23T05:04:00","date_gmt":"2026-04-23T09:04:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/04\/23\/china-linked-gopherwhisper-infects-12-mongolian-government-systems-with-go-backdoors\/"},"modified":"2026-04-24T06:30:11","modified_gmt":"2026-04-24T10:30:11","slug":"china-linked-gopherwhisper-infects-12-mongolian-government-systems-with-go-backdoors","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/04\/23\/china-linked-gopherwhisper-infects-12-mongolian-government-systems-with-go-backdoors\/","title":{"rendered":"China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/china-linked-gopherwhisper-infects-12.html\">China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/china-linked-gopherwhisper-infects-12.html\">https:\/\/thehackernews.com\/2026\/04\/china-linked-gopherwhisper-infects-12.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-04-23 05:04:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Apr 23, 2026<\/span><\/span><span class=\"p-tags\">Threat Intelligence \/ Malware<\/span><\/p>\n<p>Mongolian governmental institutions have emerged as the target of a previously undocumented China-aligned advanced persistent threat (APT) group tracked as <strong>GopherWhisper<\/strong>.<\/p>\n<p>&#8220;The group wields a wide array of tools mostly written in Go, using injectors and loaders to deploy and execute various backdoors in its arsenal,&#8221; Slovakian cybersecurity company ESET said in a report shared with The Hacker News. &#8220;GopherWhisper abuses legitimate services, notably Discord, Slack, Microsoft 365 Outlook, and file.io for command-and-control (C&#038;C) communication and exfiltration.&#8221;<\/p>\n<p>The group was first discovered in January 2025 following the discovery of a never-before-seen backdoor codenamed LaxGopher on a system belonging to a Mongolian governmental entity. GopherWhisper is assessed to be active at least since November 2023. Besides LaxGopher, some of the other malware families part of the threat actor&#8217;s arsenal are Golang-based tools to receive instructions from the C&#038;C server, execute them, and send the results back.<\/p>\n<p>Also used by the threat actor is a file collection tool to gather files of interest and exfiltrate them in compressed format to the file[.]io file sharing service and a C++ backdoor that offers remote control over compromised hosts.<\/p>\n<p>Telemetry data from ESET shows that about 12 systems associated with the Mongolian governmental institution were infected by the backdoors, with C&#038;C traffic from the attacker-controlled Discord and Slack servers indicating dozens of other victims.<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"754\" data-original-width=\"1073\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhezmThtbQaAIr1oji9r1qi7xmhJcbkHN77X7k14XQm-EwAtlpHIDflocEAqjoanruHZh9Vs7p1lHXQkN4ch_XR3MrhCd5aO-KHlObqSOdd2u4CmwpNHgdmjlmJJE_OlBu6Yapamyh69WV88qdG1SCbuGHopvjQPjJxDrxB2iyYJPPISzM-UNah1k3SblKk\/s1600\/go.jpg\"\/><\/p>\n<p>Exactly how GopherWhisper obtains initial access to the target networks is currently not known. But a successful foothold is followed by attempts to deploy a wide range of tools and implants &#8211;<\/p>\n<ul>\n<li><strong>JabGopher<\/strong>, an injector that executes the LaxGopher (&#8220;whisper.dll&#8221;) backdoor.<\/li>\n<li><strong>LaxGopher<\/strong>, a Go-based backdoor that uses Slack for C2 to execute commands via &#8220;cmd.exe&#8221; and publish the results back to the Slack channel, as well as download&#8230;<\/li>\n<\/ul>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/china-linked-gopherwhisper-infects-12.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors https:\/\/thehackernews.com\/2026\/04\/china-linked-gopherwhisper-infects-12.html Publish Date: 2026-04-23 05:04:00&#8230;<\/p>\n","protected":false},"author":1,"featured_media":235060,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgcPZEHQ2ePgeeD1JO3nqkHDxu5XWd53XZ8GsPxgX5Gl3vY-isf7bdT1_8ZGbMGOwic5gJKYXp0G5rIiSacQvidnb3_voREgqsyanhwo0uQs1HLNXACrsV2tLmHXlxA4FizErdbwb5o35MEDIrZKMkDsAAzIVPt0g6pTMbsZSN7SIwTEozmgX7MO26XxapY\/s1600\/chinese-hacking.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,35,32,34],"class_list":["post-235059","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-hacker","tag-malware","tag-threat-actor"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/235059"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=235059"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/235059\/revisions"}],"predecessor-version":[{"id":235061,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/235059\/revisions\/235061"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/235060"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=235059"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=235059"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=235059"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}