logo

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

ID: 33dd3034-bc33-5c64-9af4-2a90280dab93

STIX ID: report--33dd3034-bc33-5c64-9af4-2a90280dab93

Feed Name: Securelist by Kaspersky

Threat Score
88/100

Date Published: 2026-07-16

Date Updated: 2026-07-23

Author: Noushin Shabab

...
...

This report documents an ongoing, sophisticated espionage campaign (late 2025–May 2026) targeting government and diplomatic entities in Southeast Asia using a family of Go-based RATs (GoSerpent, McMx, Stowaway), credential-dumping tools (Mimikatz, QuarksDumpLocalHash), and a two-stage exfiltration pipeline (ThumbcacheService -> TmcLoader/TmcPayload). The actor established persistent access, proxied traffic via SOCKS5 to pivot and mask operations, collected and archived sensitive documents, and used harvested credentials and hosted configuration files to move the archives to remote network shares; the report provides technical IOCs (file hashes, C2 IPs), TTP details, and suggests a possible link to the TetrisPhantom actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.