INTEL_REPORT
ESET WeLiveSecurity · published 4/23/2026, 8:59:18 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
GopherWhisper: A burrow full of malware ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions GopherWhisper: A burrow full of malware Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEATURED Uk…
https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware
sha256:af3dee611183f75f860adda96087be012ee07b3c485c144c1b7ce7a45a57af34
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| Open → |
| url | https://github.com/NHAS/stab | Open → |
| url | https://github.com/kirinlabs/utils | Open → |
| url | https://github.com/wumansgy/goEncrypt | Open → |