GoSerpent Backdoor Drives a Patient Cyber Espionage Campaign Against Southeast Asian Governments
ID: 8ee1aa9f-d392-5a9a-968d-471afbfdeadc
STIX ID: report--8ee1aa9f-d392-5a9a-968d-471afbfdeadc
Feed Name: securityonline.info
Threat Score
Kaspersky GReAT disclosed a long-running GoSerpent-based cyber espionage campaign active since at least 2021 against Southeast Asian government and diplomatic networks; operators establish long dwell time footholds, use credential dumpers and ThumbcacheService for staged collection, then deploy Stowaway and TmcLoader/TmcPayload for covert exfiltration via SOCKS5 proxies and network-share transfers, with published hashes and C2 IPs for defender hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
