Security
Kaspersky researchers have uncovered a cyber-espionage campaign using a previously undocumented remote access trojan (RAT) called GoSerpent to target government and diplomatic organizations in Southeast Asia, highlighting a stealthy approach designed to evade detection and enable long-term intelligence gathering.
The campaign, identified by Kaspersky's Global Research and Analysis Team (GReAT) in July 2026, uses a combination of the GoSerpent backdoor, TmcLoader and Stowaway malware to establish persistent access and exfiltrate sensitive information from compromised systems.
According to the researchers, GoSerpent is a Go-based remote access trojan that has been active since at least 2021, with the latest variant observed this year. The malware employs persistence mechanisms and disguises itself as legitimate system processes to reduce the chances of detection.
"What stands out about GoSerpent is the deliberate dwell time. Usually, attackers want to move quickly once they get a foothold, but this group drops the initial backdoor and waits," said Noushin Shabab, lead security researcher at Kaspersky GReAT.
"They let the dust settle for weeks before deploying their secondary exfiltration tools like TmcLoader. That kind of patience is a calculated move designed to outlast standard log retention policies and automated security sweeps, making it incredibly difficult for defenders to connect the initial infection to the eventual data theft," Shabab added.
Kaspersky said the campaign reflects a well-planned intelligence-gathering operation focused on maintaining long-term access to victim environments before initiating data theft. The delayed deployment of secondary malware enables attackers to avoid triggering security monitoring systems that typically focus on the initial stages of an intrusion.
The researchers also noted similarities between the GoSerpent campaign and the TetrisPhantom threat actor, citing common targeting patterns, technical capabilities and operational methods. However, the company said further investigation is underway before making a definitive attribution.
The findings underscore the continued evolution of advanced persistent threat (APT) campaigns, where attackers are relying on patience, persistence and multi-stage malware deployments rather than rapid attacks to compromise high-value government and diplomatic targets.
The campaign, identified by Kaspersky's Global Research and Analysis Team (GReAT) in July 2026, uses a combination of the GoSerpent backdoor, TmcLoader and Stowaway malware to establish persistent access and exfiltrate sensitive information from compromised systems.
According to the researchers, GoSerpent is a Go-based remote access trojan that has been active since at least 2021, with the latest variant observed this year. The malware employs persistence mechanisms and disguises itself as legitimate system processes to reduce the chances of detection.
"What stands out about GoSerpent is the deliberate dwell time. Usually, attackers want to move quickly once they get a foothold, but this group drops the initial backdoor and waits," said Noushin Shabab, lead security researcher at Kaspersky GReAT.
"They let the dust settle for weeks before deploying their secondary exfiltration tools like TmcLoader. That kind of patience is a calculated move designed to outlast standard log retention policies and automated security sweeps, making it incredibly difficult for defenders to connect the initial infection to the eventual data theft," Shabab added.
Kaspersky said the campaign reflects a well-planned intelligence-gathering operation focused on maintaining long-term access to victim environments before initiating data theft. The delayed deployment of secondary malware enables attackers to avoid triggering security monitoring systems that typically focus on the initial stages of an intrusion.
The researchers also noted similarities between the GoSerpent campaign and the TetrisPhantom threat actor, citing common targeting patterns, technical capabilities and operational methods. However, the company said further investigation is underway before making a definitive attribution.
The findings underscore the continued evolution of advanced persistent threat (APT) campaigns, where attackers are relying on patience, persistence and multi-stage malware deployments rather than rapid attacks to compromise high-value government and diplomatic targets.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




