China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks
2026-04-25T19:24:07Z•0516c62229e38c9cbd4a58f8d01ad8f212a5d8784611522815b064d4cb216c82
APTBitwardenCheckmarxChinaCisco firewallCrowdStrikeFast16FirestarterGoGopherWhisperICS/OTLogScale","NessusShai-HuludTeamPCPTenablebackdoorgovernment targetsinjectorsloadersnpmpatchespersistencesabotage malwaresupply chainvulnerabilities
What happened
Multiple high-impact incidents and trends reported: China-linked APT “GopherWhisper” leverages Go-based backdoors, custom loaders/injectors and abuses legitimate services to target government organizations; a pre‑Stuxnet-era sabotage malware family dubbed “Fast16” targeted high‑precision calculation software and included self‑propagation; a US federal agency’s Cisco firewall was found infected with a persistent ‘Firestarter’ backdoor providing remote access; a Bitwarden npm package was compromised in a supply‑chain attack tied to Checkmarx/TeamPCP and the Shai‑Hulud worm. Vendors patched high‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 0516c62229e38c9cbd4a58f8d01ad8f212a5d8784611522815b064d4cb216c82
- Enrichment time
- 2026-04-25T19:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.