GopherWhisper Turns Collaboration Tools Into Espionage Channels
The real problem is not one backdoor or one platform. GopherWhisper gives itself multiple command channels across Slack, Discord, Outlook drafts, and file.io, so blocking a single service does not break operator control or stop exfiltration.
ESET tied the China-aligned group to an intrusion at a Mongolian government entity and found about 12 infected systems there, with telemetry suggesting dozens more victims. The toolkit is mostly Go-based, with a C++ backdoor, and each implant uses a different legitimate service or channel for command-and-control and data theft.
That design makes the campaign resilient. If one collaboration service is cut off, the others still carry commands or stolen files, which raises the odds that access persists inside government networks longer than defenders expect.