news.mlab.sh
Back to the feed
threat-intel

New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage

High
Summary

A previously undocumented Go-based malware, GoSerpent, has been actively targeting government and diplomatic entities in Southeast Asia since 2021, with a renewed surge in activity in 2026. Developed by the threat actor group TetrisPhantom (linked to DoNot Team), GoSerpent utilizes a chain of sophisticated tools – including Stowaway, Mimikatz, and ThumbcacheService – to steal sensitive data and establish long-term access, leveraging techniques like hardware encryption and remote template injection.

Cybersecurity researchers have uncovered a previously undocumented malware called GoSerpent that has been actively targeting government and diplomatic entities in Southeast Asia since 2021, with a renewed surge in activity in May 2026. Russian cybersecurity company Kaspersky identified the activity, noting that it shares targeting, technical capabilities, and operational overlaps with TetrisPhantom, a “highly skilled and resourceful threat actor” first documented in October 2023 as targeting government entities in the Asia-Pacific (APAC) region. GoSerpent employs a sophisticated chain of tools to achieve its goals, including Stowaway, Mimikatz, and ThumbcacheService.

GoSerpent functions by receiving encrypted and Base64-encoded command-line arguments containing the C2 address and communication password. Once decrypted, the backdoor connects to the C2 server over an encrypted connection, where the SHA256 hash of the communication password serves as the encryption key. The malware’s capabilities include establishing SOCKS5 proxy servers for traffic routing, deploying additional malicious tools like McMx RAT, and executing commands such as alerting the server of an active infection, starting a listening port, closing a listening port, connecting to a remote server, spawning a shell on the infected machine, uploading files, downloading files, starting a SOCKS5 proxy, and forwarding to a connected node.

Specifically, Stowaway is a proxy and remote access tool with SOCKS5 proxying, port forwarding, reverse tunneling, remote shell access, file transfer, and SSH-based tunneling features. Mimikatz is used to dump memory from the Local Security Authority Subsystem Service (LSASS) process to extract credential material, and QuarksDumpLocalHash extracts local account password hashes from the SAM registry hive. The threat actors also leverage hardware encryption via secure USB drives to ensure secure data transfer between systems.

The campaign comprises various malicious modules, through which the actor can gain extensive control over the victim’s device. This allows them to execute commands, collect files and information from compromised machines, and transfer them to other machines using the same or different secure USB drives as carriers. The disclosure comes as Cyderes Howler Cell detailed a targeted cyber espionage operation orchestrated by DoNot Team targeting Bangladesh’s military and defence establishments using spear-phishing emails containing a malware-laced RTF document to drop a DLL implant that sets up scheduled-task persistence disguised as OneDrive telemetry, profiles the host, and beacons to a C2 server over HTTPS.

“What makes this threat particularly concerning is the strategic deployment of various tools with sophisticated data collection and exfiltration capabilities,” Kaspersky explained. “The chain from ThumbcacheService to TmcLoader/TmcPayload demonstrates sophisticated operational planning.”

Read the full article at The Hacker News