Kaspersky researchers detail a sophisticated two-phase cyberattack campaign targeting government and diplomatic entities in Southeast Asia, active since late 2025. The primary tool is GoSerpent, a Go-based backdoor with SOCKS5 proxy, file transfer, and remote shell capabilities, using AES-CBC and ChaCha20 encryption for C2 communications. In the initial phase, GoSerpent deploys ThumbcacheService (a DLL that silently collects and archives Office/PDF documents), Mimikatz, and QuarksDumpLocalHash for credential theft. In May 2026, attackers returned with Stowaway (an open-source-based proxy RAT) and TmcLoader/TmcPayload, a C++ loader that injects into svchost to exfiltrate the previously collected data via network shares using stolen credentials. The toolchain is tightly integrated: ThumbcacheService stores files in a specific database, and TmcPayload is hardcoded to exfiltrate that exact file. Infrastructure relies on Alibaba Cloud and UCLOUD HK. Attribution tentatively points to TetrisPhantom. IoCs including file hashes and C2 IPs are provided.
Table of contents
IntroductionTechnical detailsInfrastructureAttributionConclusionIndicators of compromise29.2K Impressions1 Comment