logo

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

ID: c84e4ed0-acaa-581e-9b01-b4b7e2339d24

STIX ID: report--c84e4ed0-acaa-581e-9b01-b4b7e2339d24

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-07-17

Date Updated: 2026-07-17

Author: [email protected] (The Hacker News)

...
...

Kaspersky reported a long-running cyber-espionage campaign targeting Southeast Asian government and diplomatic entities using a Go-based backdoor dubbed **GoSerpent** (active since 2021) that accepts encrypted/Base64 parameters, connects to C2 over an encrypted channel, and can deploy secondary tools for credential dumping and staged exfiltration (ThumbcacheService, Mimikatz, QuarksDumpLocalHash); operators returned in May 2026 with evolved implants (Stowaway, TmcLoader/TmcPayload), and the activity shows operational overlaps with known groups such as TetrisPhantom and DoNot Team.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.