GopherWhisper: new China-linked APT targets Mongolia with Go-based malware

2026-04-26T14:51:43Zf8900216be190193b30bbe18ddad1a03fda6602a0b0e05ad465ca566967cf8ea
APTBitwardenBreeze CacheCISACVE-2024-7399CVE-2026-3844CVE-2026-41651CheckmarxChina-linkedCisco ASAFIRESTARTERGoGopherWhisperKnown Exploited VulnerabilitiesMongoliaPack2TheRootTrigonaWordPressbackdoorscustom-tooldata-exfiltrationloadersnpmransomwaresupply-chain

What happened

Collection of Security Affairs reports covering multiple active threats: ESET uncovers a new China-linked APT dubbed GopherWhisper targeting Mongolian government institutions with Go-based loaders, injectors, and backdoors; Trigona ransomware actors have moved to a custom command-line exfiltration tool to speed data theft and evade detection; a critical Breeze Cache WordPress plugin vulnerability (CVE-2026-3844, CVSS 9.8) is being actively exploited at scale; CISA added several flaws (including CVE-2024-7399) to its KEV catalog. Additional notable items: persistent FIRESTARTER backdoor on a U.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
f8900216be190193b30bbe18ddad1a03fda6602a0b0e05ad465ca566967cf8ea
Enrichment time
2026-04-26T14:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.