GopherWhisper: new China-linked APT targets Mongolia with Go-based malware
2026-04-26T14:51:43Z•f8900216be190193b30bbe18ddad1a03fda6602a0b0e05ad465ca566967cf8ea
APTBitwardenBreeze CacheCISACVE-2024-7399CVE-2026-3844CVE-2026-41651CheckmarxChina-linkedCisco ASAFIRESTARTERGoGopherWhisperKnown Exploited VulnerabilitiesMongoliaPack2TheRootTrigonaWordPressbackdoorscustom-tooldata-exfiltrationloadersnpmransomwaresupply-chain
What happened
Collection of Security Affairs reports covering multiple active threats: ESET uncovers a new China-linked APT dubbed GopherWhisper targeting Mongolian government institutions with Go-based loaders, injectors, and backdoors; Trigona ransomware actors have moved to a custom command-line exfiltration tool to speed data theft and evade detection; a critical Breeze Cache WordPress plugin vulnerability (CVE-2026-3844, CVSS 9.8) is being actively exploited at scale; CISA added several flaws (including CVE-2024-7399) to its KEV catalog. Additional notable items: persistent FIRESTARTER backdoor on a U.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- f8900216be190193b30bbe18ddad1a03fda6602a0b0e05ad465ca566967cf8ea
- Enrichment time
- 2026-04-26T14:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.