GoSerpent malware targets Southeast Asian governments and diplomats for espionage

Kaspersky uncovers GoSerpent, a Go-based backdoor targeting government and diplomatic entities in Southeast Asia since late 2025 for long-term intelligence gathering.

CSBadmin
1 Min Read

Kaspersky researchers have discovered GoSerpent, a previously undocumented Go-based malware framework targeting government and diplomatic entities in Southeast Asia since late 2025. The malware establishes encrypted command-and-control communications and can deploy secondary payloads for credential dumping and sensitive data collection.

GoSerpent communicates with its C2 server over an encrypted connection where the SHA256 hash of the communication password serves as the encryption key. Its capabilities include spawning a remote shell, starting a SOCKS5 proxy, port forwarding, file upload and download, and deploying additional tools such as Mimikatz for credential extraction and QuarksDumpLocalHash for local password hash extraction.

The threat actors returned to compromised environments in May 2026 with an evolved toolset including Stowaway, a proxy and RAT with SSH tunneling; ThumbcacheService, a sophisticated file collection module; and TmcPayload, designed to exfiltrate stored sensitive data over network shares. Earlier iterations of the Go-based implant have been active since 2021.

The end goal is to harvest sensitive files from government networks for exfiltration, using credential dumping tools to move laterally through shared drives and extract intelligence from diplomatic targets.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.