JabGopher is an injector used in the GopherWhisper toolset, a China-aligned threat cluster documented by ESET. It is associated with intrusions targeting governmental institutions in Mongolia, with ESET observing deployment in January 2025 and telemetry showing about 12 affected systems in one Mongolian governmental institution; additional victims were suspected from Slack and Discord C2 traffic. JabGopher is described as a Go-based injector/backdoor injector found as whisper.dll and side-loaded by a legitimate whisper.exe. It checks for the presence of C:\ProgramData\Microsoft\EdgeUpdate\Log\backup.log before continuing, decrypts an embedded LaxGopher payload from PE resources, launches a new svchost.exe process, and injects the LaxGopher backdoor into that process using process hollowing. LaxGopher, which JabGopher executes, is a Go-based backdoor that communicates with operators via a private Slack server, can execute commands through cmd.exe, upload files, download additional payloads such as CompactGopher, and change its Slack token and channel ID. JabGopher is part of a broader GopherWhisper arsenal that also includes RatGopher, BoxOfFriends, FriendDelivery, CompactGopher, and SSLORDoor. The sample whisper.dll has been detected as Win64/Injector.UI and described as the JabGopher backdoor injector. High-confidence associated artifact: filename whisper.dll.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
JabGopher is an injector that executes the LaxGopher backdoor.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
JabGopher masquerades as a legitimate Windows service, using the display name Windows Push Notification Local Service.
JabGopher, LaxGopher, CompactGopher, RatGopher, and SSLORDoor all have encryption/decryption capabilities.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An injector used to deploy LaxGopher into svchost.exe on compromised systems.
An injector associated with LaxGopher, used by GopherWhisper in attacks against Mongolian government targets.
An injector used to execute the LaxGopher backdoor on compromised systems.
A custom injector used by GopherWhisper as part of its toolset for maintaining access to targeted systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.