ESET researchers have identified a new China-aligned APT group named GopherWhisper that is targeting governmental institutions in Mongolia. This group utilizes a variety of tools primarily written in Go, including backdoors such as LaxGopher, RatGopher, and BoxOfFriends, along with injectors, loaders, and exfiltration tools. The threat actors leverage legitimate services like Discord, Slack, Microsoft 365 Outlook, and file.io for command and control communication and data exfiltration.
Through the analysis of C&C traffic from Slack and Discord channels associated with the attackers, ESET Research gained valuable insights into the operations and activities of GopherWhisper. The group’s toolset includes various malicious components like JabGopher, CompactGopher, and SSLORDoor, each serving a specific purpose within the attack chain.
During the investigation, researchers discovered that the group’s Slack and Discord servers were used for testing the functionality of the backdoors before being repurposed as C&C servers for actual compromised machines. The C&C communications revealed commands for disk and file enumeration, as well as links to GitHub repositories containing malicious code used as resources during development.
Overall, the discovery of GopherWhisper highlights the sophisticated tactics and techniques employed by threat actors aligned with China in targeting governmental entities, emphasizing the importance of vigilance and proactive cybersecurity measures. Hey there,
We uncovered some interesting details during our investigation into GopherWhisper. It turns out that the operator behind the scenes was using a virtual machine based on VMware, booted and installed in the UTC+8 time zone.
But that’s not all – we also dug into Microsoft 365 Outlook communication and found some juicy tidbits. By tapping into email messages through the Microsoft Graph API, we stumbled upon a welcome email that was never deleted. This email revealed that the account barrantaya.1010@outlook[.]com was created on July 11th, 2024, just 11 days before the FriendDelivery DLL – the loader for BoxOfFriends – was created on July 22nd, 2024.
Our deep dive into GopherWhisper exposed an APT group armed with a diverse arsenal of custom tools. By dissecting their C&C communications from Slack, Discord, and Outlook, we gained valuable insights into their operations and activities post-compromise.
For a more detailed breakdown of the tools and C&C traffic, check out our full white paper. And if you’re on the hunt for indicators of compromise (IoCs), head over to the white paper or our GitHub repository for a comprehensive list.
Stay informed, stay vigilant.
Cheers,
[Your Name]
