CyberSecurityBoardThreat Intel · CVEs · Products
Malware

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

July 17, 2026

Cybersecurity researchers at Kaspersky have uncovered a previously undocumented malware called GoSerpent, used since late 2025 in cyber attacks targeting government and diplomatic entities in Southeast Asia. The malware is a Go-based backdoor and remote access trojan (RAT) that communicates with an external command-and-control (C2) server to deploy secondary payloads for sensitive data collection and credential dumping.

GoSerpent receives encrypted and Base64-encoded command-line arguments containing the C2 address and communication password. Once decrypted, it connects to the C2 server over an encrypted connection using the SHA256 hash of the password as the encryption key. Supported commands include alerting the server of an active infection, starting/stopping listening on specific ports, connecting to remote servers, spawning a shell, uploading/downloading files, starting a SOCKS5 proxy, and forwarding to connected nodes.

The attackers also deploy additional tools: ThumbcacheService for file collection, Mimikatz for credential dumping, and QuarksDumpLocalHash for local account password hash extraction. In May 2026, the threat actors returned with an evolved set of tools including Stowaway RAT (a proxy and remote access tool), TmcLoader (a C++ loader), and TmcPayload (for exfiltrating stored sensitive data).

Kaspersky notes that earlier iterations of the Go-based implant have been used since 2021 against victims in Southeast Asia. The campaign shares targeting, technical capabilities, and operational overlaps with TetrisPhantom, a threat actor first documented in October 2023 targeting government entities in the Asia-Pacific region using secure USB drives as carriers.

In a related disclosure, Cyderes Howler Cell detailed a targeted cyber espionage operation by DoNot Team targeting Bangladesh’s military and defence establishments using spear-phishing emails with a malware-laced RTF document to drop a DLL implant.

Attack groups: TetrisPhantom, DoNot Team

Malware: GoSerpent, ThumbcacheService, Mimikatz, QuarksDumpLocalHash, Stowaway, TmcLoader, TmcPayload, McMx RAT

Companies: Kaspersky, Cyderes Howler Cell