
GopherWhisper APT: New State-Backed Actor Exploits SaaS Ecosystem to Breach Western Government Networks
A newly identified APT group, GopherWhisper, is utilizing a sophisticated Go-based toolkit to weaponize legitimate SaaS platforms like Slack and Discord for stealthy command-and-control operations against government targets.
Encrygma is selling the entire Full Cyber Weapon Research of GopherWhisper APT: New State-Backed Actor Exploits SaaS Ecosystem to Breach Western Government Networks for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- State Cyber Warfare
- Severity:
- High
- Actor Type:
- Nation-State
- Geography:
- Global
- Confidence:
- High Confidence
- Source:
- Microsoft MSTIC
- Read Time:
- 5 min
Executive Summary
Encrygma Intelligence has tracked a surge in activity from a previously undocumented state-backed threat actor, designated as GopherWhisper. Over the last 48 hours, new telemetry indicates that this group has successfully breached at least three Western government ministries and a major defense contractor. The group utilizes a novel Go-based malware suite designed to blend into legitimate network traffic by abusing the APIs of popular SaaS platforms, including Slack, Discord, and Microsoft 365 Outlook, for command-and-control (C2) communications.
Threat Analysis
GopherWhisper represents a significant evolution in 'Living-off-Trusted-Services' (LOTS) tactics. Unlike traditional APTs that rely on dedicated C2 infrastructure which can be easily blacklisted, GopherWhisper leverages the inherent trust organizations place in cloud-based collaboration tools. By tunneling data through encrypted HTTPS requests to legitimate Slack channels or Discord servers, the actor effectively bypasses traditional perimeter defenses and signature-based intrusion detection systems. This campaign appears focused on long-term strategic espionage, specifically targeting diplomatic communications and sensitive defense procurement data.
Technical Details
The primary payload is a modular Go-based implant that performs initial reconnaissance before establishing a persistent connection. The malware uses a technique known as 'API-Hopping,' where it rotates its C2 channel between different SaaS providers to avoid detection by traffic volume anomalies. For instance, it may use Slack for heartbeat signals and Discord for large-scale data exfiltration. Technical analysis reveals the use of custom obfuscation layers that hide the API keys within the binary's memory space, making static analysis difficult. Furthermore, the group has been observed using 'ClickFix' social engineering tactics to gain initial access, persuading high-value targets to execute malicious scripts under the guise of fixing browser compatibility issues.
Attribution Assessment
While GopherWhisper is a new designation, preliminary analysis by Microsoft MSTIC and Unit 42 suggests a strong nexus to East Asian state interests. The group's code overlaps significantly with the 'Salt Typhoon' and 'Volt Typhoon' clusters, particularly in its use of Go-based networking libraries and its focus on critical infrastructure reconnaissance. However, the specific focus on SaaS-based C2 suggests a specialized sub-unit or a new generation of operators trained in cloud-native exploitation. We assess with moderate confidence that GopherWhisper is a state-sponsored entity operating in support of regional geopolitical objectives.
Implications
The emergence of GopherWhisper signals a crisis of trust for the SaaS ecosystem. As government agencies increasingly migrate to cloud-based collaboration, the attack surface expands beyond the reach of traditional firewalls. The ability of an actor to remain undetected for months within a Slack workspace highlights the urgent need for behavioral-based monitoring of API traffic. If left unaddressed, these tactics will allow nation-states to maintain persistent, invisible access to the most sensitive layers of government administration.
Recommendations
Encrygma recommends that organizations immediately implement granular API monitoring for all collaboration platforms. Security teams should look for unusual patterns of outbound HTTPS traffic to Slack and Discord domains, particularly from servers or workstations that do not typically require such access. Additionally, implementing a Zero Trust architecture that requires multi-factor authentication (MFA) for all internal service communications can mitigate the risk of lateral movement. Finally, network defenders should prioritize the patching of webmail services and public-facing routers, as these remain primary entry points for initial GopherWhisper intrusions.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

GopherWhisper APT Escalates Global Espionage Campaign Targeting Government Infrastructure

Jewelbug APT Expands Espionage and Crypto Fraud Operations Across Middle East and Asia

