CyberMaterial

CyberMaterial

Threats

GopherWhisper APT

The APT That Turns SaaS Into a Command Channel

CyberMaterial's avatar
Sofia's avatar
CyberMaterial and Sofia
Jun 20, 2026
∙ Paid

Cyber espionage is no longer confined to hidden servers and suspicious domains. A recently disclosed threat group, GopherWhisper, shows how modern attackers are shifting command-and-control operations into the same tools enterprises use every day.

Instead of relying on traditional infrastructure, this group operates through platforms like Slack, Discord, and Microsoft 365, blending into normal business traffic by design.


What is GopherWhisper?


GopherWhisper is a China-aligned advanced persistent threat (APT) group identified by ESET researchers.

It was publicly documented in 2025–2026 reporting and is associated with cyberespionage activity targeting government organizations, including entities in Mongolia.

Rather than focusing on disruption or ransomware, the group’s objective is long-term intelligence collection and stealthy access.


This Substack is reader-supported. To receive new posts and support our work, consider becoming a free or paid subscriber.


Watch Summary Video Below: ⬇️

User's avatar

Continue reading this post for free, courtesy of CyberMaterial.

Or purchase a paid subscription.
© 2026 CyberMaterial · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture