Kaspersky researchers have discovered GoSerpent, a previously undocumented Go-based malware framework targeting government and diplomatic entities in Southeast Asia since late 2025. The malware establishes encrypted command-and-control communications and can deploy secondary payloads for credential dumping and sensitive data collection.
GoSerpent communicates with its C2 server over an encrypted connection where the SHA256 hash of the communication password serves as the encryption key. Its capabilities include spawning a remote shell, starting a SOCKS5 proxy, port forwarding, file upload and download, and deploying additional tools such as Mimikatz for credential extraction and QuarksDumpLocalHash for local password hash extraction.
The threat actors returned to compromised environments in May 2026 with an evolved toolset including Stowaway, a proxy and RAT with SSH tunneling; ThumbcacheService, a sophisticated file collection module; and TmcPayload, designed to exfiltrate stored sensitive data over network shares. Earlier iterations of the Go-based implant have been active since 2021.
The end goal is to harvest sensitive files from government networks for exfiltration, using credential dumping tools to move laterally through shared drives and extract intelligence from diplomatic targets.
