🌐 Nation-State Threats

China APT 'GopherWhisper' Abuses Cloud Services [New Tactic]

Think your data's safe because it's tucked away in the cloud? Think again. A new hacking outfit from China is proving that the digital tools we rely on can just as easily become our undoing.

Abstract digital network lines representing cyber attack pathways.

⚡ Key Takeaways

  • China-linked APT group GopherWhisper is using legitimate services (Slack, Discord, Microsoft Graph API) for C&C and data exfiltration. 𝕏
  • This 'shadow infrastructure hacking' tactic makes attacks harder to detect by blending in with normal network traffic. 𝕏
  • The group has deployed various tools including LaxGopher, CompactGopher, RatGopher, and BoxOfFriends, targeting government entities. 𝕏
Wei Chen
Written by

Wei Chen

Technical security analyst. Specialises in malware reverse engineering, APT campaigns, and incident response.

Worth sharing?

Get the best Cybersecurity stories of the week in your inbox — no noise, no spam.

Originally reported by SecurityWeek

Stay in the loop

The week's most important stories from Threat Digest, delivered once a week.