The real break is the dwell time. GoSerpent is built to keep a government or diplomatic compromise alive long enough to steal credentials, route traffic through the host, and stage files for later removal, so cleaning one backdoor does not clear the stolen material already queued up.
Kaspersky says the malware has been used since late 2025 against Southeast Asian government and diplomatic targets, with a more evolved toolset appearing in May 2026. That set added a Stowaway RAT, a proxy tool, and a stealthy exfiltration component, alongside credential dumpers and shared-drive staging through network shares.
That turns the incident into a persistence problem as much as an intrusion problem. The operator can sit on harvested files for months and move them out later through normal-looking internal file movement, which extends the blast radius beyond the implant still on disk.