GopherWhisper is a China-linked APT group targeting government institutions in Mongolia. Use services like Discord, Slack, Microsoft 365 Outlook, and file.io for C&C communications and data exfiltration. The toolkit includes Go and C++ backdoors, loaders, and exfiltration tools. Attackers' channel traffic and post-compromise activities were also analysed
ESET researchers have discovered a previously unknown China-aligned APT group that has been named GopherWhisper. The group uses a wide range of tools, mostly written in Go, that employ injectors and loaders to deploy and execute various backdoors in their arsenal. In the observed campaign, the threat actors targeted a government institution in China. GopherWhisper leverages legitimate services, specifically Discord, Slack, Microsoft 365 Outlook, and file.io, for command and control (C&C) communications and data exfiltration.
ESET identified the group in January 2025, when it found a previously undocumented backdoor, which ESET researchers named LaxGopher, in the system of a government agency in China. As they investigated further, they managed to discover several other malicious tools, mainly various additional backdoors, all distributed by the same group. Most of these tools were written in Go and had cyber espionage as a common goal.
According to ESET telemetry findings, the facility affected by the GopherWhisper backdoors is a Chinese government agency. By analyzing the C&C traffic coming from the Discord and Slack servers managed by the attackers, ESET estimates that, in addition to the Chinese entity, dozens of other victims were also affected, although no information is available on their geographical location or sectors to which they belong.
Of the seven tools discovered, four are backdoors: LaxGopher, RatGopher and BoxOfFriends, written in Go, and SSLORDoor, written in C++. Additionally, ESET identified an injector (JabGopher), a Go-based exfiltration tool (CompactGopher), and a malicious DLL file (FriendDelivery).
Poiché il set di malware individuato da ESET non presentava somiglianze di codice con i tool di altri soggetti noti e non vi era alcuna sovrapposizione nelle tattiche, tecniche e procedure (TTP) già utilizzate, ESET ha attribuito questi tool a un nuovo gruppo. I ricercatori hanno scelto di chiamare il gruppo GopherWhisper poiché la maggior parte degli strumenti utilizzati era scritta in linguaggio Go, che ha come mascotte uno scoiattolo chiamato gopher, e in base al nome del file whisper.dll, che veniva caricato separatamente.
GopherWhisper si distingue per l’ampio ricorso a servizi legittimi quali Slack, Discord e Outlook per le comunicazioni C&C. «Nel corso dell’indagine, abbiamo estratto migliaia di messaggi su Slack e Discord, oltre a bozze di e-mail da Microsoft Outlook. I dati ci hanno fornito una visione approfondita del funzionamento interno del gruppo», afferma Eric Howard, researcher di ESET che ha rilevato il gruppo di hacker.
«L’analisi dei timestamp dei messaggi su Slack e Discord ci ha mostrato che la maggior parte degli stessi veniva inviata durante l’orario di lavoro, ovvero tra le 8:00 e le 17:00, il che corrisponde all’ora standard cinese. Inoltre, anche l’impostazione locale per l’utente configurato nei metadati di Slack era impostata su questo fuso orario. Riteniamo quindi che GopherWhisper sia un gruppo legato alla Cina», spiega Howard.
Sulla base dell’indagine condotta da ESET, i server Slack e Discord del gruppo sono stati inizialmente utilizzati per testare la funzionalità delle backdoor e, successivamente, senza cancellare i log, sono stati impiegati anche come server C&C per le backdoor LaxGopher e RatGopher su diversi computer compromessi. Oltre alle comunicazioni su Slack e Discord, i ricercatori di ESET sono stati in grado di estrarre anche i messaggi e-mail utilizzati per la comunicazione tra la backdoor BoxOfFriends e il suo C&C utilizzando l’API Microsoft Graph.
Eric Howard di ESET Research ha presentato questi risultati alla conferenza Botconf 2026.






