Securelist
Read post

GoSerpent backdoor attacks in Southeast Asia

Kaspersky researchers detail a sophisticated two-phase cyberattack campaign targeting government and diplomatic entities in Southeast Asia, active since late 2025. The primary tool is GoSerpent, a Go-based backdoor with SOCKS5 proxy, file transfer, and remote shell capabilities, using AES-CBC and ChaCha20 encryption for C2 communications. In the initial phase, GoSerpent deploys ThumbcacheService (a DLL that silently collects and archives Office/PDF documents), Mimikatz, and QuarksDumpLocalHash for credential theft. In May 2026, attackers returned with Stowaway (an open-source-based proxy RAT) and TmcLoader/TmcPayload, a C++ loader that injects into svchost to exfiltrate the previously collected data via network shares using stolen credentials. The toolchain is tightly integrated: ThumbcacheService stores files in a specific database, and TmcPayload is hardcoded to exfiltrate that exact file. Infrastructure relies on Alibaba Cloud and UCLOUD HK. Attribution tentatively points to TetrisPhantom. IoCs including file hashes and C2 IPs are provided.

    #golang#malware
Jul 16•9m read time•From securelist.com
Post cover image
Table of contents
IntroductionTechnical detailsInfrastructureAttributionConclusionIndicators of compromise
29.2K Impressions1 Comment
Securelist's image
Securelist

Securelist is a cybersecurity blog and research platform operated by Kaspersky Lab. It offers insigh...

74 Followers

•

164 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard