ESET disclosed a previously undocumented, China-aligned APT group dubbed GopherWhisper after uncovering an intrusion affecting about 12 systems at a Mongolian governmental institution, with command-and-control traffic indicating there may be dozens of additional victims. The campaign relied on a largely Go-based malware arsenal—including the LaxGopher backdoor, loaders, injectors, file collection and exfiltration tools, and a C++ backdoor called SSLORDoor—to maintain access and move data after compromise. The initial access vector remains unknown, but investigators first identified the activity in January 2025 on a Mongolian government system.
The group concealed malicious communications inside trusted enterprise traffic by abusing Slack, Discord, Microsoft 365 Outlook draft messages via the Microsoft Graph API, direct encrypted traffic over port 443, and file.io for exfiltration and C2 support. ESET said recovered Slack and Discord API tokens, along with thousands of operator messages and Outlook drafts, exposed the attackers’ development workflow, testing environments, and operational mistakes. Metadata such as UTC+8 working hours and locale settings supported the assessment that the actor is China-aligned, while Outlook artifacts showed infrastructure timing including creation of the mailbox barrantaya.1010@outlook[.]com and compilation of the FriendDelivery DLL in July 2024.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On publication of its findings, ESET disclosed the new China-aligned APT group GopherWhisper, detailing its use of collaboration and cloud services to hide command-and-control traffic and exfiltration. The report also described recovered Slack and Discord tokens, thousands of operator messages and Outlook drafts, and the basis for attributing the actor as China-aligned.
ESET added a dedicated malware-IoC repository entry for GopherWhisper, publishing indicators and naming components including CompactGopher, RatGopher, SSLORDoor, JabGopher, FriendDelivery, and BoxOfFriends. The entry also listed supporting tools and identified an SSLORDoor command-and-control server at 43.231.113[.]50 first seen on 2025-03-24.
ESET first identified the previously undocumented group in January 2025 after discovering the new LaxGopher backdoor on a Mongolian government system. Subsequent analysis linked the intrusion to a broader Go-heavy malware toolkit and abuse of Slack, Discord, Outlook, and file.io.
A China-aligned threat actor later named GopherWhisper infected about 12 systems belonging to a Mongolian governmental institution. ESET also observed command-and-control traffic suggesting there may have been dozens of additional victims.
Outlook artifacts revealed the compilation of the FriendDelivery DLL, a component associated with GopherWhisper's toolset. The timestamp helped establish part of the group's malware development timeline.
Artifacts recovered by ESET showed the Outlook mailbox barrantaya.1010@outlook[.]com, later used in GopherWhisper operations, was created. This mailbox was part of the group's use of Outlook draft messages via Microsoft Graph API for command-and-control support.
ESET's report states the China-aligned GopherWhisper group had been active since at least November 2023. This establishes an earlier known start for the campaign than previously reflected in the timeline.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcescworld.com
Open sourcetechjacksolutions.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceinfosec.pub
Open sourcegithub.com
Open sourceweb-assets.esetstatic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.