Security researchers have uncovered a sophisticated cyber espionage campaign that uses a newly documented malware family called GoSerpent to target government agencies and diplomatic organizations across Southeast Asia. The operation has been active since late 2025, although researchers found earlier versions of the malware dating back to 2021. The campaign is designed to quietly collect sensitive information and maintain long-term access inside compromised networks.

russian-government-office-goserpent-malware-target

The attackers begin by deploying the GoSerpent backdoor, which is written in the Go programming language. This malware communicates with its command-and-control server using encrypted channels, making its activity difficult to detect. Researchers found that the latest version hides its configuration using encrypted command-line arguments, showing that the operators have continued improving the malware to avoid security tools.

Once the backdoor is active, it downloads additional malicious tools to gather valuable information from infected systems. One of these tools, called ThumbcacheService, searches for important documents including Word files, Excel spreadsheets and PDF files. The collected files are compressed, password-protected and stored locally so they can be stolen later without immediately raising suspicion.

goserpent-malware-encrypted-command-and-control-analysis

The campaign also focuses heavily on stealing credentials from compromised computers. To achieve this, the attackers deploy well-known tools such as Mimikatz and QuarksDumpLocalHash, which extract passwords, cached credentials and account hashes. These stolen credentials later help the attackers move through the victim’s network and access shared systems that contain additional sensitive information.

Researchers observed that after the initial compromise, the attackers often wait for several weeks before launching the next stage of the operation. During this time, the malware silently continues collecting files while avoiding suspicious activity. This patient approach suggests the attackers are focused on intelligence gathering rather than causing immediate disruption or attracting attention.

cybersecurity-analyst-monitoring-government-espionage-attack

In the second stage of the campaign, the attackers introduce another Go-based tool known as Stowaway, which acts as both a remote access Trojan and a proxy utility. Stowaway supports features such as remote shell access, port forwarding, file transfers and encrypted communications. It is then used to deliver additional malware, including TmcLoader and TmcPayload, which are responsible for moving the collected data out of the victim’s environment.

Researchers also noticed several technical similarities between GoSerpent and the newer Stowaway tools, indicating that both were likely developed by the same threat actor. Some tactics, techniques and operational patterns resemble activity previously associated with the TetrisPhantom threat group. However, the researchers have not officially attributed the campaign and say further investigation is required before confirming any connection.

goserpent-mobile-malware-cyber-threat-warning

Overall, the GoSerpent campaign highlights a well-planned and highly coordinated espionage operation targeting governments and diplomatic organizations in Southeast Asia. Its combination of encrypted communications, credential theft, stealthy file collection and staged data exfiltration demonstrates a strong focus on long-term intelligence gathering. Researchers recommend that organizations strengthen endpoint monitoring, detect unusual credential activity, and closely watch for suspicious network behavior to defend against similar advanced threats.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news