FriendDelivery is a malicious DLL loader and injector associated with the China-aligned GopherWhisper threat group. It was discovered in February 2025 on the same Mongolian government victim where ESET also found LaxGopher, RatGopher, and SSLORDoor. FriendDelivery’s role is to install and execute the BoxOfFriends backdoor in memory. Reported samples include wer.dll, detected as Win64/Injector.G. The malware copies itself as wer.dll and a legitimate WerFault.exe renamed as bdreinit.exe into %APPDATA%\BitDifender\ and installs the bdreinitsvc Windows service for persistence. It decrypts the BoxOfFriends payload from an overlay in wer.dll using a null-preserving XOR operation with key 0x56 and injects it into help.exe. BoxOfFriends, which FriendDelivery loads, is a Go-based backdoor that uses Microsoft 365 Outlook via Microsoft Graph API and draft email messages for bidirectional command-and-control. The broader GopherWhisper campaign targeted governmental institutions in Mongolia, and ESET assessed the actor as China-aligned based on zh-CN locale metadata and operator activity patterns consistent with UTC+8 working hours. The content does not provide a distinct initial infection vector for FriendDelivery itself beyond its use as a loader/injector within this intrusion set.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We discovered FriendDelivery, an injector for the backdoor BoxOfFriends, in February 2025 at the same victim where we found LaxGopher, RatGopher, and SSLORDoor.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The supporting tools handle the rest of the chain. JabGopher and FriendDelivery load the backdoors into memory... It also contained links to public GitHub repositories covering... process injection on x86 and x64...
JabGopher masquerades as a legitimate Windows service, using the display name Windows Push Notification Local Service.
FriendDelivery disguises its service with the name bdreinitsvc, which resembles a service related to Bitdefender products.
FriendDelivery is stored in %AppData%\App within the legitimate directory of Bitdefender.
The supporting tools handle the rest of the chain. JabGopher and FriendDelivery load the backdoors into memory... It also contained links to public GitHub repositories covering... process injection on x86 and x64...
BoxOfFriends is a Go binary that is injected into the legitimate Windows executable help.exe.
CompactGopher runs its own cleanup process by deleting both the cleartext and encrypted archives... BoxOfFriends selfdelete... the file used in the injection process will be deleted.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A loader used to execute BoxOfFriends; the report states the FriendDelivery DLL was created on July 22, 2024.
A loader used to deploy the BoxOfFriends backdoor in GopherWhisper operations.
A malicious DLL used as a loader and injector to deploy BoxOfFriends.
A custom loader used by GopherWhisper in the described espionage campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.