New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
ID: c84e4ed0-acaa-581e-9b01-b4b7e2339d24
STIX ID: report--c84e4ed0-acaa-581e-9b01-b4b7e2339d24
Feed Name: The Hacker News
Kaspersky reported a long-running cyber-espionage campaign targeting Southeast Asian government and diplomatic entities using a Go-based backdoor dubbed **GoSerpent** (active since 2021) that accepts encrypted/Base64 parameters, connects to C2 over an encrypted channel, and can deploy secondary tools for credential dumping and staged exfiltration (ThumbcacheService, Mimikatz, QuarksDumpLocalHash); operators returned in May 2026 with evolved implants (Stowaway, TmcLoader/TmcPayload), and the activity shows operational overlaps with known groups such as TetrisPhantom and DoNot Team.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
