Attackers are hiding command-and-control traffic inside Slack and Discord while simultaneously experimenting with post-quantum encryption in ransomware payloads. Both of those stories landed this week, and together they tell you something uncomfortable: the threat surface keeps expanding, but the entry points stay embarrassingly predictable.

How GopherWhisper Actually Works
ESET researchers tied GopherWhisper to an intrusion at a Mongolian governmental entity, with the group’s toolset built almost entirely in Go. That’s not an accident — Go compiles to a single static binary, has minimal dependencies, and cross-compiles effortlessly across platforms. Twelve government systems confirmed compromised. Those are the ones they found.
The clever part isn’t the malware itself. It’s the exfiltration and C2 channel.
GopherWhisper routes its command-and-control traffic through Slack workspaces, Discord servers, Outlook draft folders, and file.io. Your network security tools are likely configured to trust all of those. Slack and Discord traffic looks like your developers chatting. Outlook drafts don’t even generate outbound traffic in the traditional sense — a shared mailbox with unread drafts is as stealthy as it gets. File.io is a file-sharing service that thousands of legitimate workflows use daily.
This is the real problem with APT-level tradecraft: they don’t knock on a door you’re watching. They walk in through a door you propped open yourself.
Kyber Ransomware Wants a Future Nobody Can Decrypt

Separately, a new ransomware operation called Kyber has started targeting Windows systems and VMware ESXi endpoints. One variant is already implementing Kyber1024, a post-quantum key encapsulation mechanism standardized by NIST. This is not theoretical future-proofing — they’re using it now, in active attacks.
What that means in practice is genuinely alarming. Current law enforcement and vendor-assisted decryption efforts frequently depend on weaknesses in the cryptographic implementations ransomware groups use. Sloppy RSA key handling, reused IVs, hardcoded seeds — researchers have cracked ransomware families on exactly these flaws. Post-quantum algorithms like Kyber1024, implemented correctly, don’t have those weaknesses in the same way. If this group irons out their implementation, the “we got the decryption keys from law enforcement” recovery path gets much harder.
The attack vectors, though? Still the usual suspects.
- Exposed RDP and SSH ports with weak or default credentials
- Phishing emails delivering initial loaders
- Unpatched VMware ESXi instances reachable from the internet
- Credential stuffing against internet-facing admin panels
The encryption may be cutting-edge. The access methods are not.
Where IPBan Fits Into Both of These Stories
Here’s the through-line that connects GopherWhisper and Kyber despite their very different profiles: both attacks require an initial network connection to succeed. GopherWhisper needs to drop loaders and establish its C2 beaconing. Kyber ransomware needs to authenticate against an exposed service. Neither attack happens in a vacuum — they both involve an IP address making a connection to something you’re running.
That’s exactly the layer where IPBan operates. Automated brute-force protection and IP banning don’t care how sophisticated your encryption scheme is, and they don’t need to recognize your malware by signature. They watch for behavioral signals — repeated failed authentication attempts, scanning patterns, connections from known-malicious ranges — and they cut access before the attacker gets a foothold.
Against Kyber ransomware specifically, that matters. If your ESXi management interface isn’t getting hammered by credential stuffing because the attacking IPs got auto-blocked at attempt three or four, the ransomware never runs. Post-quantum encryption is irrelevant if the attacker never gets in.
Against GopherWhisper, the calculus is different but the principle holds. Initial loader delivery still requires network access. Blocking aggressive reconnaissance IPs, scanning ranges, and known APT infrastructure before a loader ever executes is a real disruption — not a complete defense, but a meaningful one. The group’s C2 obfuscation is impressive only after they’ve established presence. Denying that presence is where the fight starts.
If you’re running exposed services — and almost everyone is — IPBan Pro gives you automated threat protection at the edge that runs 24/7 without a human watching a dashboard. That’s not a replacement for good network segmentation or patching cadence. It’s the layer that does the unglamorous work while your team focuses on the harder problems.
Frequently Asked Questions
- Can IP banning actually stop an APT like GopherWhisper?
- Not entirely, no. APT groups rotate infrastructure and use legitimate platforms to obscure C2 traffic. What IP banning can do is disrupt the initial access phase — blocking scanning IPs, credential stuffing sources, and known-malicious ranges before loaders are delivered. It raises the cost of the operation without being a silver bullet.
- Is Kyber1024 post-quantum encryption actually a threat to current defenses?
- It’s a meaningful escalation, not an overnight catastrophe. Most ransomware decryption wins come from implementation flaws, not broken algorithms. A well-implemented Kyber1024 scheme closes those windows. The bigger concern is that this signals ransomware groups are thinking ahead, which means defenders need to be doing the same.
- Why do ransomware groups keep using predictable access methods even when their tools are sophisticated?
- Because they don’t need to be creative about access when defenders aren’t forcing them to be. Exposed RDP, default credentials, and unpatched ESXi hosts are still everywhere. Until defenders make those entry points consistently painful, there’s no incentive for attackers to change their approach.
Sources
- China-Linked GopherWhisper Infects 12 Mongolian Government Systems with Go Backdoors — The Hacker News
- GopherWhisper APT group hides command and control traffic in Slack and Discord — Help Net Security
- Kyber ransomware gang toys with post-quantum encryption on Windows — BleepingComputer
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
