Threats · 59 days ago
The real break is the dwell time. GoSerpent is built to keep a government or diplomatic compromise alive long enough to steal credentials, route traffic through the host, and stage files for later removal, so cleaning one backdoor does not clear the stolen material already queued up.
Kaspersky says the malware has been used since late 2025 against Southeast Asian government and diplomatic targets, with a more evolved toolset appearing in May 2026. That set added a Stowaway RAT, a proxy tool, and a stealthy exfiltration component, alongside credential dumpers and shared-drive staging through network shares.
That turns the incident into a persistence problem as much as an intrusion problem. The operator can sit on harvested files for months and move them out later through normal-looking internal file movement, which extends the blast radius beyond the implant still on disk.
2 sources covering this story
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
New GoSerpent malware targets Southeast Asian government and diplomatic entities, deploying SOCKS5 proxies, credential dumpers, and data theft tools.
GoSerpent backdoor attacks in Southeast Asia
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.
Part of the PlainSec briefing for 2026-07-18