mimile
mimile.ai
Back to feed
This event is part of a larger story
Массовые утечки и атаки: июль 2026 года
Read briefing

GoSerpent malware targets Southeast Asian governments since late 2025

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

GoSerpent malware targets Southeast Asian governments since late 2025

Kaspersky discovered a new malware called GoSerpent targeting government and diplomatic entities in Southeast Asia since late 2025. The malware is designed for long-term access, data collection, and credential dumping. In May 2026, attackers deployed an evolved set of tools including a new RAT and proxy tool.

Malware Capabilities

GoSerpent communicates with a command-and-control (C2) server using encrypted and Base64-encoded arguments. It supports commands to alert infection, start/close listening ports, spawn a shell, upload/download files, and establish SOCKS5 proxies. The malware can deploy additional tools like ThumbcacheService for file collection, Mimikatz for credential dumping, and QuarksDumpLocalHash for password hash extraction.

Attack Evolution

Earlier versions of the Go-based implant and RAT have been used since 2021 against Southeast Asian victims. In May 2026, attackers introduced an evolved set including Stowaway RAT and a proxy tool resembling the initial malware, along with ThumbcacheService for exfiltrating data collected over previous months. The goal is to harvest sensitive files and stage them for exfiltration via network shared drives.

What's Next

Kaspersky continues to monitor the threat actor's activities. It remains unclear whether the attacks will expand to other regions or target additional sectors.

1 source

GoSerpent malware targets Southeast Asian governments since late 2025