China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks

2026-04-25T19:24:07Z0516c62229e38c9cbd4a58f8d01ad8f212a5d8784611522815b064d4cb216c82
APTBitwardenCheckmarxChinaCisco firewallCrowdStrikeFast16FirestarterGoGopherWhisperICS/OTLogScale","NessusShai-HuludTeamPCPTenablebackdoorgovernment targetsinjectorsloadersnpmpatchespersistencesabotage malwaresupply chainvulnerabilities

What happened

Multiple high-impact incidents and trends reported: China-linked APT “GopherWhisper” leverages Go-based backdoors, custom loaders/injectors and abuses legitimate services to target government organizations; a pre‑Stuxnet-era sabotage malware family dubbed “Fast16” targeted high‑precision calculation software and included self‑propagation; a US federal agency’s Cisco firewall was found infected with a persistent ‘Firestarter’ backdoor providing remote access; a Bitwarden npm package was compromised in a supply‑chain attack tied to Checkmarx/TeamPCP and the Shai‑Hulud worm. Vendors patched high‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
0516c62229e38c9cbd4a58f8d01ad8f212a5d8784611522815b064d4cb216c82
Enrichment time
2026-04-25T19:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.