Thursday, June 11, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

ESET Research discovers new China-aligned group, GopherWhisper: It abuses messaging services Discord, Slack, and Outlook to spy

April 23, 2026
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 6 mins read
5
SHARES
249
VIEWS
Share on TwitterShare on LinkedInShare on Facebook
  • ESET Research has uncovered a new China-aligned APT group, which has been named GopherWhisper, that targets governmental institutions in Mongolia.
  • GopherWhisper leverages Discord, Slack, Microsoft 365 Outlook, and file.io for command and control (C&C) communications and exfiltration.
  • The group’s toolset includes custom Go-based backdoors, injectors, exfiltration tools, loader FriendDelivery, and a C++ backdoor.
  • ESET analyzed C&C traffic from the attacker’s Slack and Discord channels, gaining information about the group’s internal operations and post-compromise activities.

BRATISLAVA, Slovakia, April 23, 2026 (GLOBE NEWSWIRE) — ESET researchers have discovered a previously undocumented China-aligned APT group that they named GopherWhisper. The group wields a wide array of tools, mostly written in Go, that use injectors and loaders to deploy and execute various backdoors in its arsenal. In the observed campaign, the threat actors targeted a governmental institution in Mongolia. GopherWhisper abuses legitimate services, notably Discord, Slack, Microsoft 365 Outlook, and file.io, for command and control (C&C) communication and exfiltration.

ESET discovered the group in January 2025, when it found a previously undocumented backdoor, which ESET researchers named LaxGopher, in the system of a government institution in Mongolia. Digging deeper, they managed to uncover several more malicious tools, mainly various additional backdoors, all deployed by the same group. The majority of these tools were written in Go, and their collective aim was cyberespionage.

According to ESET telemetry, the victim impacted by GopherWhisper backdoors is a Mongolian governmental institution. By analyzing the C&C traffic from the attacker-operated Discord and Slack servers, ESET estimates that dozens of other victims besides the Mongolian institution were also affected, though it has no information about their geolocation or verticals.

Of the seven tools that were discovered, four are backdoors — LaxGopher, RatGopher, and BoxOfFriends, written in Go, and SSLORDoor, written in C++. Furthermore, ESET found an injector (JabGopher), a Go-based exfiltration tool (CompactGopher), and a malicious DLL file (FriendDelivery).

Since the set of malware ESET found bore no code similarities to any known threat actor’s tools, and there was also no overlap in the Tactics, Techniques, and Procedures (TTPs) used by any other group, ESET decided to attribute the tools to a new group. Researchers chose to name that group GopherWhisper due to the majority of the group’s tools’ being written in the Go programming language, which has a gopher as its mascot, and based on the filename of whisper.dll, which is side-loaded.

GopherWhisper is characterized by the extensive use of legitimate services such as Slack, Discord, and Outlook for C&C communication. “During our investigation, we managed to extract thousands of Slack and Discord messages, as well as several draft email messages from Microsoft Outlook. This gave us great insight into the inner workings of the group,” says ESET researcher Eric Howard, who discovered the new threat group.

“Timestamp inspection of the Slack and Discord messages showed us that the bulk of them were being sent during working hours, i.e. between 8 a.m. and 5 p.m., which aligns with China Standard Time. Furthermore, the locale for the configured user in Slack metadata was also set to this time zone. We therefore believe that GopherWhisper is a China-aligned group,” explains Howard.

Based on this ESET investigation, the group’s Slack and Discord servers were first used to test the functionality of the backdoors, and then later, without clearing the logs, also used as C&C servers for the LaxGopher and RatGopher backdoors on multiple compromised machines. In addition to the Slack and Discord communications, ESET researchers were also able to extract email messages used for communication between the BoxOfFriends backdoor and its C&C using the Microsoft Graph API.

ESET Research’s Eric Howard presented these findings at Botconf 2026 conference.

For a more detailed analysis of the new GopherWhisper threat group and its arsenal, check out the latest ESET Research blogpost and white paper “GopherWhisper: A burrow full of malware” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

About ESET

ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown — securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit http://www.eset.com, or follow our social media, podcasts, and blogs.

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.
ShareTweet1ShareSendShare2
Previous Post

Mobile Vikings subscriptions hub powered by the Digital Vending Machine® from Bango

Next Post

Patton Unveils Powerful New US-Manufactured FiberPlex™ 12G-SDI Fiber Extender Kits

Related Posts

Crypto Market News: AlphaPepe Presale Advances CoinGecko Listing as XRP Price Prediction Hits $7.00

MONACO, June 10, 2026 (GLOBE NEWSWIRE) -- Crypto market news is turning toward AlphaPepe after the project submitted its CoinGecko listing as launch preparations continue to move forward. The presale has now crossed $1.49 million in total capital raised, Stage 17 is live at $0.01877, and holder growth has passed...

Read moreDetails

AI Search Engineers Launches AI Search Visibility Audit Targeting the Three Industries with the Highest AI Recommendation Gap: Legal, Medical, and Financial Services

New audit service identifies exact AI search visibility gaps for law firms, medical practices, and financial advisors, the three professional service categories where AI-generated recommendations are most commercially significant and most underserved by existing digital marketing strategies AMHERST, NY / ACCESS Newswire / June 10, 2026 / AI Search Engineers,...

Read moreDetails

Genuity Subsidiary Millmerran Operating Company and ISN® Celebrate 10-Year Partnership Advancing Contractor and Supplier Compliance

DALLAS, June 10, 2026 (GLOBE NEWSWIRE) -- ISN, the global leader in contractor and supplier information management services, announced the 10-year milestone of its partnership with Millmerran Operating Company, a subsidiary of Genuity and the operator of a coal-fired power station in Queensland, Australia. Since first implementing ISNetworld, Millmerran Operating...

Read moreDetails

CORRECTION FROM SOURCE: Dot Ai Announces Two Letters of Intent for Strategic Preferred Stock Investment and to Sell a Portion of its Operating Business

Proposed transactions are the result of the Company's previously announced strategic alternatives process and, if consummated, would strengthen the balance sheet with up to a $5 million investment in convertible preferred stock and an up to $6 million asset purchase along with the assumption of up to $3 million of...

Read moreDetails

Ai4 2026 Unveils Expanded Exhibit Hall Featuring Nearly 400 Exhibitors, New Interactive Experiences, and the Industry’s Leading AI Companies

Show Floor to Feature Startup Innovation, Global AI Participation, and New Agentic AI Demonstrations LAS VEGAS, NV / ACCESS Newswire / June 10, 2026 / Ai4 2026, America's largest AI industry conference taking place August 4-6, 2026 at The Venetian in Las Vegas, announced a significantly expanded Exhibit Hall experience...

Read moreDetails

Xtract One Announces Fiscal 2026 Third Quarter Results

Revenue of $10.3 million, up nearly 200% year-over-year Adjusted EBITDA1 of $0.6 million and positive operating cash flow before working capital Gross margin of 61%, improved from 57% year-over-year Solid total backlog of $45.1 million TORONTO, June 10, 2026 (GLOBE NEWSWIRE) -- Xtract One Technologies Inc. (TSX: XTRA) (OTCQX: XTRAF)...

Read moreDetails

BIO-key Receives Notice of Non-Compliance from Nasdaq Related to Delay of its Form 10-Q Filing

HOLMDEL, N.J., June 10, 2026 (GLOBE NEWSWIRE) -- BIO-key International, Inc. (OTC Markets: BKYI), a global leader in Identity and Access Management (IAM) and biometric authentication technologies, announced today that it has received a notification letter from The Nasdaq Stock Market, LLC informing the Company that it was not in compliance...

Read moreDetails

VigorPeak [URGENT REPORT 2026] Vigor Peak Male Performance Capsules Shocking Boom Why Everyone Is Talking About This Male Vitality Supplement

Largo, FL, June 10, 2026 (GLOBE NEWSWIRE) --  A newly released industry report is drawing attention to the rapid growth of the men's wellness sector, with analysts citing increased consumer interest in health, fitness, confidence, and healthy aging as major drivers of market expansion throughout 2026. Unlock New Male Wellness...

Read moreDetails

Rumble Announces Participation in Upcoming June 2026 Conferences

LONGBOAT KEY, FL, June 10, 2026 (GLOBE NEWSWIRE) -- Rumble Inc. (NASDAQ: RUM) (“Rumble” or the “Company”), the Freedom-First technology platform, today announced that its management team will participate in the following upcoming conferences: Maxim Group’s AI Data Center Summit, to be held virtually on Thursday, June 11, 2026. Chris...

Read moreDetails

Solidion Technology Announces Closing of $35 Million Private Placement of Common Stock Priced Above Market Under Nasdaq Rules

Proceeds fully fund the company through 2028 and will be used to accelerate commercialization of Solidion’s patented Extreme-Climate Battery Technology targeting the Lunar economy and space applications DALLAS, June 10, 2026 (GLOBE NEWSWIRE) -- Solidion Technology Inc. ("Solidion" or the "Company") (NASDAQ: STI), an advanced battery technology solutions provider, today...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • GENISOM AI Debuts at ICRA 2026 with Full-Stack Embodied Intelligence System

    14 shares
    Share 6 Tweet 4
  • Top Cross-Chain DeFi Solutions to Watch by 2025

    122 shares
    Share 49 Tweet 31
  • Top Layer 1 Crypto Projects to Watch in 2025

    14 shares
    Share 6 Tweet 4
  • NVIDIA and SK hynix Announce Multiyear Technology Partnership to Advance Memory for AI Factories

    7 shares
    Share 3 Tweet 2
  • Understanding Soulbound Tokens SBT Their Definition and Significance

    63 shares
    Share 25 Tweet 16
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • Crypto Market News: AlphaPepe Presale Advances CoinGecko Listing as XRP Price Prediction Hits $7.00
  • AI Search Engineers Launches AI Search Visibility Audit Targeting the Three Industries with the Highest AI Recommendation Gap: Legal, Medical, and Financial Services
  • Route1 Inc. Adopts Shareholder Rights Plan
  • Genuity Subsidiary Millmerran Operating Company and ISN® Celebrate 10-Year Partnership Advancing Contractor and Supplier Compliance
  • CORRECTION FROM SOURCE: Dot Ai Announces Two Letters of Intent for Strategic Preferred Stock Investment and to Sell a Portion of its Operating Business

RSS Latest on Block3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age

RSS Latest on Meta3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Founder’s Note
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Web3Wire Whitepaper | Tokenomics

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!

The Klyrox Protocol | The Algorithmic Monographs

Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News

Media Portfolio: Block3Wire | Meta3Wire

  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.