GopherWhisper China-aligned APT campaign targeting Mongolian government institutions
Campaign
Summary
Hide ▲
Show ▼
The GopherWhisper campaign is a China-aligned APT operation targeting Mongolian governmental institutions, and it now appears to extend beyond a single compromise to dozens of other victims. The activity matters because it combines covert remote execution, file theft, and multi-service command-and-control across legitimate platforms. Investigators linked at least about 12 systems at one government entity to the operation after a new backdoor surfaced in January 2025.
Related Happenings
Webworm multi-country targeting campaign against government and enterprise victims
Campaign
H score38
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Webworm multi-country targeting campaign against government and enterprise victims
CampaignAbout this happening: Webworm is running a multi-country targeting campaign against government agencies and enterprises, expanding the risk of persistent access across several regions. The...
Webworm EchoCreep and GraphWorm backdoor expansion
Malware Activity
H score28
First: 20.05.2026 15:51
Last: 20.05.2026 15:51
Sources 1
About this happening:
Webworm expanded its malware arsenal in 2025 with the custom backdoors EchoCreep and GraphWorm, increasing its ability to run stealthy command-and-control oper...
Webworm EchoCreep and GraphWorm backdoor expansion
Malware ActivityAbout this happening: Webworm expanded its malware arsenal in 2025 with the custom backdoors EchoCreep and GraphWorm, increasing its ability to run stealthy command-and-control oper...
MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy
Campaign
H score37
First: 06.05.2026 16:02
Last: 06.05.2026 16:02
Sources 1
About this happening:
The MuddyWater campaign used Microsoft Teams social engineering and a Chaos ransomware decoy to gain access, steal credentials, and establish persistence. The operatio...
MuddyWater Microsoft Teams social-engineering campaign with Chaos ransomware decoy
CampaignAbout this happening: The MuddyWater campaign used Microsoft Teams social engineering and a Chaos ransomware decoy to gain access, steal credentials, and establish persistence. The operatio...
UAT-8302 government-targeting campaign across South America and southeastern Europe
Campaign
H score28
First: 05.05.2026 17:19
Last: 05.05.2026 17:19
Sources 1
About this happening:
The UAT-8302 campaign has been tied to attacks on government entities in South America and southeastern Europe, showing a multi-region operation with post-exploita...
UAT-8302 government-targeting campaign across South America and southeastern Europe
CampaignAbout this happening: The UAT-8302 campaign has been tied to attacks on government entities in South America and southeastern Europe, showing a multi-region operation with post-exploita...
APT28 Windows Shell LNK campaign targeting Ukraine and E.U. nations
Campaign
H score39
First: 28.04.2026 08:50
Last: 28.04.2026 08:50
Sources 1
About this happening:
A December 2025 APT28 campaign targeted Ukraine and E.U. nations with a malicious Windows Shortcut (LNK) chain that bypassed Microsoft Defender SmartScreen...
APT28 Windows Shell LNK campaign targeting Ukraine and E.U. nations
CampaignAbout this happening: A December 2025 APT28 campaign targeted Ukraine and E.U. nations with a malicious Windows Shortcut (LNK) chain that bypassed Microsoft Defender SmartScreen...
Timeline
-
23.04.2026 12:04 1 articles · 2mo ago
BoxOfFriends Outlook account creation
Technical Analysis UpdateAn Outlook account used for BoxOfFriends command-and-control was created on July 11, 2024, marking an early infrastructure milestone for the Go-based backdoor that uses the Microsoft Graph API to craft draft emails with hard-coded credentials.
Show sources
- China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors — thehackernews.com — 23.04.2026 12:04
-
23.04.2026 12:04 2 articles · 2mo ago
GopherWhisper disclosure and victim scope
Initial DisclosureOn 2026-04-23, ESET disclosed GopherWhisper as a China-aligned APT targeting Mongolian governmental institutions, saying about 12 systems at one institution were infected while Discord and Slack command-and-control traffic indicated dozens of other victims; the group used LaxGopher, JabGopher, CompactGopher, RatGopher, SSLORDoor, FriendDelivery, and BoxOfFriends, and abused Discord, Slack, Microsoft 365 Outlook, Microsoft Graph API, and file[.]io for command-and-control, exfiltration, and remote execution.
Show sources
- China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors — thehackernews.com — 23.04.2026 12:04
- New GopherWhisper APT group abuses Outlook, Slack, Discord for comms — www.bleepingcomputer.com — 23.04.2026 15:06