Connect with us

Hi, what are you looking for?

HEADLINES

New cyber spy targets government and diplomatic networks in SEA – Kaspersky

In July 2026, researchers from the Kaspersky Global Research and Analysis Team (GReAT) team identified a new campaign, dubbed GoSerpent, representing a sophisticated and adaptive threat focused on the collection and exfiltration of sensitive data.

The new GoSerpent RAT targeted government and diplomatic entities in Southeast Asia. The campaign underscores the threat actor’s emphasis on maintaining long-term access and conducting intelligence collection.

In July 2026, researchers from the Kaspersky Global Research and Analysis Team (GReAT) team identified a new campaign, dubbed GoSerpent, representing a sophisticated and adaptive threat focused on the collection and exfiltration of sensitive data. According to the researchers, the operation relies on a set of customized tools, including the GoSerpent backdoor, Stowaway, and TmcLoader, reflecting a high level of technical capability and operational planning.

A central component of the campaign is the GoSerpent backdoor, a sophisticated Go-based Remote Access Trojan (RAT) that has reportedly been active since at least 2021, with the latest known variant deployed in 2026. The malware incorporates strong persistence mechanisms and uses filenames that imitate legitimate system processes to reduce the likelihood of detection.

“What stands out about GoSerpent is the deliberate dwell time. Usually, attackers want to move quickly once they get a foothold, but this group drops the initial backdoor and waits. They let the dust settle for weeks before deploying their secondary exfiltration tools like TmcLoader. That kind of patience is a calculated move designed to outlast standard log retention policies and automated security sweeps, making it incredibly difficult for defenders to connect the initial infection to the eventual data theft,” — says Noushin Shabab, Lead Security Researcher in Kaspersky GReAT.

The company’s researchers suspect a link between the GoSerpent campaign and the TetrisPhantom threat actor based on shared victimology, technical capabilities, and operational methods. While there are similarities, further investigation is ongoing to definitively attribute the campaign.

Advertisement. Scroll to continue reading.

To stay safe, Kaspersky GReAT experts recommend organizations:

  • Remain highly vigilant against the deployment of GoSerpent IoCs and other tools presented in the report.

  • Apply cybersecurity solutions that enable government agencies worldwide to regain full control over their data, ensure compliance with local regulations, and build resilient, sovereign digital infrastructures. Such options are provided by Kaspersky solutions like:

  • Kaspersky Next which enables unified real-time protection, threat visibility, investigation and the response capabilities of EDR and XDR.

  • Kaspersky Security for Mail Server which safeguards email communications through anti-phishing, attachment sandboxing, and business email compromise protection.

  • Kaspersky Digital Footprint Intelligence which monitors the external attack surface and dark web for exposed credentials, offering government teams an outside-in view of their risk landscape.

  • Kaspersky Compromise Assessment, Managed Detection and Response and Incident Response which help protect against evasive cyberattacks, investigate incidents and provide additional expertise if companies lack cybersecurity workers.

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

APAC consumers are more concerned about digital tech usage for crime than consumers globally (35% vs 32%). The awareness is highest in Thailand (39%),...

HEADLINES

“It is the time for Radenta to demonstrate that it is strongly committed to protecting client data,” remarks Nereo Bolante, Co-Director, Radenta Ethics, Compliance, and Governance Team...

HEADLINES

Password guessing and valid account misuse rank among the most effective tactics used by cyber criminals in 2025. This trend reflects a strategic shift,...

HEADLINES

"Free WiFi feels convenient, but it often comes at a hidden cost. Cybercriminals know that public networks require no authentication, making it easy for...

HEADLINES

Security leaders need to understand how AI is being weaponized, invest in AI-powered protection that is genuinely integrated into daily security workflows and approach...

HEADLINES

Stalkerware refers to software programs, apps and devices that enable someone to secretly spy on another person’s private life via their mobile device. The abuser can...

HEADLINES

The vulnerability resides in the BootROM – firmware embedded at the hardware level. Attackers could potentially get access to any data stored on the...

HEADLINES

Trust in cybersecurity vendors is fragile, difficult to measure, and increasingly shaping risk posture at both operational and board levels.

Advertisement