A long-running espionage campaign targeted government and diplomatic entities in Southeast Asia using GoSerpent, a Go-based backdoor that researchers say has been active since late 2025, with earlier variants seen against regional victims as far back as 2021. The malware established persistence as a Windows service and used stealth features including encrypted arguments, obfuscated strings, and payload execution inside svchost, while command-and-control infrastructure was hosted through legitimate providers to blend in with normal traffic.
The operators used GoSerpent to deploy follow-on tooling for file collection, credential dumping, proxying, and data theft, and later returned with an expanded toolkit that included Stowaway and the TmcLoader/TmcPayload exfiltration chain. Researchers said the activity showed deliberate coordination across intrusion stages, from initial backdoor access through credential theft and staged exfiltration, and noted a possible but unconfirmed connection to the TetrisPhantom threat actor.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
In May 2026, the operators returned with an updated toolkit that included Stowaway and the TmcLoader/TmcPayload exfiltration chain. The change showed deliberate coordination between collection, credential theft, and data exfiltration components.
The campaign was discovered in February 2026, according to the report. Researchers identified GoSerpent being used alongside tools for file collection, credential dumping, proxying, and later-stage exfiltration.
A sophisticated espionage campaign targeting government and diplomatic entities in Southeast Asia was active since late 2025. The operation centered on a Go-based backdoor called GoSerpent and supporting tooling for collection and credential theft.
The report says earlier variants of the GoSerpent backdoor were used against victims in Southeast Asia as far back as 2021. This is presented as prior activity related to the malware family discussed in the campaign.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.