
Government and diplomatic entities across Southeast Asia are facing a sophisticated cyber-espionage threat designed to stealthily collect and exfiltrate sensitive data over extended periods.
Researchers from the Kaspersky Global Research and Analysis Team (GReAT) uncovered the operation, dubbed GoSerpent, in July 2026. The threat actors rely on a set of customized tools—including the GoSerpent backdoor, Stowaway, and TmcLoader—reflecting high-level technical capabilities and deliberate operational planning.
At the core of the campaign is the GoSerpent backdoor, a Go-based Remote Access Trojan (RAT) that has been active since at least 2021, with its latest variant deployed in 2026. To minimize detection risks, the malware employs robust persistence mechanisms and disguises itself using filenames that mimic legitimate system processes.
Rather than exfiltrating data immediately upon access, the group behind GoSerpent uses extreme patience as a strategic tactic to bypass standard defense protocols.
“What stands out about GoSerpent is the deliberate dwell time. Usually, attackers want to move quickly once they get a foothold, but this group drops the initial backdoor and waits. They let the dust settle for weeks before deploying their secondary exfiltration tools like TmcLoader. That kind of patience is a calculated move designed to outlast standard log retention policies and automated security sweeps, making it incredibly difficult for defenders to connect the initial infection to the eventual data theft,” says Noushin Shabab, Lead Security Researcher in Kaspersky GReAT.
Kaspersky researchers suspect a potential link between the GoSerpent campaign and the known threat actor TetrisPhantom, citing shared victimology, technical capabilities, and operational methods. However, investigation remains ongoing to confirm definitive attribution.
To defend against GoSerpent and similar evasive cyber threats, security experts recommend that organizations implement several core defenses:
- Monitor Indicators of Compromise: Remain vigilant for GoSerpent IoCs and related custom tools across internal networks.
- Deploy Real-Time Endpoint Protection: Utilize EDR and XDR capabilities to maintain unified visibility, investigation, and response.
- Secure Mail Infrastructure: Implement advanced email security with anti-phishing, attachment sandboxing, and protection against business email compromise.
- Track External Attack Surfaces: Leverage digital footprint intelligence to monitor dark web activity, exposed credentials, and external vulnerabilities.
- Utilize Managed Security Services: Engage compromise assessment, managed detection and response, and incident response teams to bridge internal skills gaps and neutralize evasive attacks.





Leave a Reply