# GopherWhisper: A burrow full of malware

DevFeed: [GopherWhisper: A burrow full of malware](<https://devfeed.tech/articles/gopherwhisper-a-burrow-full-of-malware-8372.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/>)

Author: Eric Howard

Published: 2026-04-23T08:59:18Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [backdoor](<https://devfeed.tech/topics/backdoor.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [C++](<https://devfeed.tech/topics/c-plus-plus.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [apt](<https://devfeed.tech/tags/apt.md>), [backdoor](<https://devfeed.tech/tags/backdoor.md>), [c-plus-plus](<https://devfeed.tech/tags/c-plus-plus.md>), [china](<https://devfeed.tech/tags/china.md>), [discord](<https://devfeed.tech/tags/discord.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [go](<https://devfeed.tech/tags/go.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft-365](<https://devfeed.tech/tags/microsoft-365.md>), [slack](<https://devfeed.tech/tags/slack.md>)

## AI overview

ESET Research describes GopherWhisper, a China-aligned APT group targeting a Mongolian government entity. Its largely Go-based malware toolset uses backdoors, injectors, loaders, and legitimate services including Discord, Slack, Microsoft 365 Outlook, and file.io for command-and-control and exfiltration.

## Source excerpt

ESET Research has discovered a new China-aligned APT group that we've named GopherWhisper, which targets Mongolian governmental institutions