Particle.news
Download on the App Store

GoSerpent Malware Used to Spy on Southeast Asian Governments and Diplomats

Kaspersky's mid‑July disclosure says operators reentered victims in May 2026 with new exfiltration tools that pulled months of harvested data and left attribution unresolved.

Overview

  • Kaspersky publicly disclosed the GoSerpent campaign in mid‑July, saying the previously undocumented Go-based backdoor has been used since late 2025 to maintain long-term access to government and diplomatic networks in Southeast Asia.
  • Researchers say attackers stayed dormant after initial access and then returned in May 2026 to deploy an evolved toolset — including Stowaway RAT, TmcLoader and a TmcPayload module — to retrieve and exfiltrate data collected over months.
  • GoSerpent accepts encrypted Base64 command-line configuration that uses the SHA256 hash of a password as an encryption key and supports commands for SOCKS5 proxying, port forwarding, remote shells, and file upload/download to hide operator activity and pivot through hosts.
  • The campaign chains auxiliary tools such as ThumbcacheService for staged file collection, Mimikatz and QuarksDumpLocalHash for credential harvesting, and network-share staging that together enable lateral movement and stealthy exfiltration.
  • Defenders face detection challenges because Go implants date back to 2021, operators use long dwell times to outlast log retention, attribution remains inconclusive despite overlaps with TetrisPhantom, and a separate DoNot Team spear‑phishing campaign targeting Bangladesh was reported at the same time.