GopherWhisper is a previously undocumented China-aligned advanced persistent threat group engaged in cyber espionage against Mongolian governmental institutions. Active since at least November 2023, the actor was publicly identified after compromises affecting roughly a dozen systems at a Mongolian government entity, with evidence suggesting additional victims beyond the confirmed intrusion set. No high-confidence linkage to a previously known intrusion cluster has been established. The group relies on a custom malware ecosystem composed primarily of Go-based tooling, including the backdoors LaxGopher, RatGopher, and BoxOfFriends; the injector JabGopher; the loader and injector FriendDelivery; and the exfiltration utility CompactGopher. It also operates a C++ backdoor, SSLORDoor. Across this toolset, GopherWhisper uses loaders and injectors to deploy payloads in memory, including process hollowing and DLL side-loading, and establishes persistence through service installation. A defining characteristic of GopherWhisper is its abuse of legitimate online platforms for command and control and data theft. Different implants communicate through Slack, Discord, and Microsoft 365 Outlook draft messages via Microsoft Graph, while stolen data is packaged, encrypted, and exfiltrated through a public file-sharing service. The backdoors support remote shell command execution, file upload and download, directory navigation, sleep and interval control, port forwarding, self-deletion, and additional payload delivery. SSLORDoor further supports host and drive enumeration, file manipulation, hidden command execution, and proxy-style socket connections. Observed post-compromise behavior includes file and disk enumeration, deployment of additional tooling, credential theft using browser-password extraction utilities, token impersonation, encrypted communications, and data exfiltration. Operational evidence supporting China alignment includes Chinese locale metadata and operator activity patterns concentrated in UTC+8 business hours. The actor’s dominant motivation is espionage, with targeting and tradecraft centered on covert access to government networks and theft of information rather than disruption or monetized extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
48 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
10 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cyber-espionage activity targeting Mongolian government entities using a toolkit of mainly Go-based loaders, injectors, and backdoors, while abusing legitimate cloud and communication platforms for command-and-control and data exfiltration.
Espionage-focused activity targeting government entities using a custom Go-based toolkit and legitimate cloud and messaging services for command-and-control and data exfiltration.
Chinese espionage-focused threat actor targeting Mongolian government entities, using multiple custom backdoors and diverse cloud-based command-and-control channels.
Espionage-focused intrusion activity targeting Mongolian governmental institutions using a Go-heavy malware arsenal, abusing Discord, Slack, Microsoft 365 Outlook, and file.io for command-and-control and exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.