Overview
- Kaspersky publicly disclosed the GoSerpent campaign in mid‑July, saying the previously undocumented Go-based backdoor has been used since late 2025 to maintain long-term access to government and diplomatic networks in Southeast Asia.
- Researchers say attackers stayed dormant after initial access and then returned in May 2026 to deploy an evolved toolset — including Stowaway RAT, TmcLoader and a TmcPayload module — to retrieve and exfiltrate data collected over months.
- GoSerpent accepts encrypted Base64 command-line configuration that uses the SHA256 hash of a password as an encryption key and supports commands for SOCKS5 proxying, port forwarding, remote shells, and file upload/download to hide operator activity and pivot through hosts.
- The campaign chains auxiliary tools such as ThumbcacheService for staged file collection, Mimikatz and QuarksDumpLocalHash for credential harvesting, and network-share staging that together enable lateral movement and stealthy exfiltration.
- Defenders face detection challenges because Go implants date back to 2021, operators use long dwell times to outlast log retention, attribution remains inconclusive despite overlaps with TetrisPhantom, and a separate DoNot Team spear‑phishing campaign targeting Bangladesh was reported at the same time.