Skip to main content
Mallory
MalwareUsed by 1 actor

LaxGopher

LaxGopher is a custom Go-based backdoor used by the China-aligned threat group GopherWhisper. ESET first detected it in January 2025 on systems belonging to a governmental entity in Mongolia, where it was deployed on roughly a dozen systems; broader Slack and Discord C2 analysis suggested additional victims may exist. LaxGopher uses a private Slack workspace/channel for command and control, retrieving instructions and posting results back to the same channel. It can execute commands via cmd.exe/Command Prompt, upload files, download additional payloads or tools, and change its configured Slack token and channel ID. ESET reported that one payload delivered through LaxGopher was CompactGopher, a Go-based exfiltration utility that compresses, encrypts, and uploads files to file.io. LaxGopher’s hardcoded Slack configuration is decrypted with AES-CFB-128 using the key "ha,just_kidding!". In observed operations, JabGopher acted as its injector: a component side-loaded as whisper.dll by a legitimate whisper.exe, which checked for C:\ProgramData\Microsoft\EdgeUpdate\Log\backup.log, decrypted an embedded LaxGopher payload from PE resources, and injected it into a new svchost.exe process using process hollowing. Recovered Slack communications associated with LaxGopher mainly contained disk and file enumeration commands. The initial access vector for the infections is not available from the provided content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
GopherWhisper

The group’s toolset that we initially discovered includes the custom Go-based backdoors LaxGopher and RatGopher, the injector JabGopher, the exfiltration tool CompactGopher, and a C++ backdoor SSLORDoor.

MITRE ATT&CK

Techniques & procedures

21 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583.006Web ServicesEvidence2

GopherWhisper uses Slack, Discord, and Microsoft Graph services for its C&C infrastructure.

Execution

3 techniques
T1059Command and Scripting InterpreterEvidence1
TacticExecution

LaxGopher communicates via Slack, runs commands, and downloads payloads

T1059.001PowerShellEvidence2
TacticExecution

The PowerShell command get-mppreference | select exclusionpath | ft -autosize run with administrative privileges, to check for Windows Defender exclusion paths...

T1059.003Windows Command ShellEvidence2
TacticExecution

LaxGopher has the following capabilities: interactively execute commands via cmd.exe... RatGopher has the following capabilities: execute a new instance of cmd.exe... SSLORDoor has the following capabilities: spawn a hidden cmd.exe.

T1055Process InjectionEvidence1

JabGopher injects LaxGopher into svchost.exe

T1055.012Process HollowingEvidence2

JabGopher can inject LaxGopher into svchost.exe.

Stealth

3 techniques
T1055Process InjectionEvidence1

JabGopher injects LaxGopher into svchost.exe

T1055.012Process HollowingEvidence2

JabGopher can inject LaxGopher into svchost.exe.

T1140Deobfuscate/Decode Files or InformationEvidence2
TacticStealth

JabGopher, LaxGopher, CompactGopher, RatGopher, and SSLORDoor all have encryption/decryption capabilities.

Discovery

4 techniques
T1007System Service DiscoveryEvidence2
TacticDiscovery

LaxGopher, RatGopher, and SSLORDoor can enumerate all services running on a compromised host.

T1082System Information DiscoveryEvidence2
TacticDiscovery

LaxGopher, RatGopher, and SSLORDoor can collect the hostname, OS version, and OS architecture of a compromised host.

T1083File and Directory DiscoveryEvidence3
TacticDiscovery

LaxGopher, RatGopher, and SSLORDoor can obtain file and directory listings.

T1518Software DiscoveryEvidence2
TacticDiscovery

LaxGopher, RatGopher, and SSLORDoor can identify running software on victim machines.

Collection

1 technique
T1005Data from Local SystemEvidence2

LaxGopher, RatGopher, SSLORDoor, and CompactGopher can collect local data from a compromised machine.

T1071Application Layer ProtocolEvidence7

Attackers continue to lean on everyday collaboration platforms to hide command and control traffic inside normal enterprise noise... running its operations through Slack workspaces, Discord servers, Outlook drafts, and the file.io sharing service.

T1071.001Web ProtocolsEvidence2

LaxGopher, RatGopher, and BoxOfFriends use HTTPS for C&C communication.

T1102Web ServiceEvidence3

GopherWhisper leverages Discord, Slack, Microsoft 365 Outlook, and file.io for C&C communications and exfiltration.

T1102.002Bidirectional CommunicationEvidence2

LaxGopher, RatGopher, and BoxOfFriends use Slack, Discord, and Microsoft Graph, respectively, for C&C infrastructure.

T1105Ingress Tool TransferEvidence5

LaxGopher, RatGopher, and SSLORDoor can all download additional files/payloads.

T1132.001Standard EncodingEvidence2

LaxGopher and RatGopher use base64 to encode messages sent to their C&Cs.

T1573.001Symmetric CryptographyEvidence2

LaxGopher and RatGopher use AES algorithms for encryption. BoxOfFriends uses XOR encryption.

Exfiltration

2 techniques
T1041Exfiltration Over C2 ChannelEvidence1

LaxGopher, RatGopher, SSLORDoor, and BoxOfFriends exfiltrate data to their C&Cs.

T1567Exfiltration Over Web ServiceEvidence3

LaxGopher leverages Slack to exfiltrate data. RatGopher leverages Discord and file.io to exfiltrate data. CompactGopher uses the file.io web service to exfiltrate data.

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
1 tracked

IPs, domains, and DNS infrastructure linked to this family.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app1 month ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping21

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.