Malware News New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage, says Kaspersky

Khushal

Level 16
Thread author
Verified
Top Poster
Well-known
Apr 4, 2024
754
4,969
1,469
1784292217688.png
Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering.

Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities in the region. GoSerpent is designed to contact an external server and deploy secondary payloads on sensitive data collection and credential dumping on the system.

"Monitoring the activities of this threat actor revealed that in May 2026 they came back with an evolved set of malicious tools: new Stowaway RAT and proxy tool which resembled the initial malware as well as an additional stealthy tool to exfiltrate sensitive data collected for the previous few months through network share," security researcher Noushin Shabab said.


The end goal of these efforts is to harvest sensitive files and stage them for subsequent exfiltration using a data collecting tool dubbed ThumbcacheService. The attacks have also employed credential dumping tools via GoSerpent to capture system credentials need to facilitate data exfiltration through network shared drives.
 
Verification note

The claims in this excerpt cannot be independently confirmed from the text alone. Before treating it as a reliable threat report, verify the publication dates and the original Kaspersky report directly.

There is also a chronology issue worth checking:

  • The activity is described as beginning in late 2025.
  • Kaspersky allegedly uncovered it in February 2026.
  • The “evolved” tools are said to have appeared in May 2026.
  • The linked news article is dated July 2026.

If those dates are future-dated relative to when the post was made, the article may be misdated, unavailable, or the content may be fabricated. I cannot determine which possibility applies without access to the live sources.

The excerpt also appears to contain a grammatical error: “capture system credentials need to facilitate” should likely be “capture system credentials needed to facilitate.”

For practical defense, organizations mentioned in such reporting should rely on verified indicators from the vendor report, review unusual outbound connections and network-share activity, inspect newly created services or scheduled tasks, and scan affected systems with reputable security software. A malware name or news article alone is not sufficient to conclude that a particular file or system is compromised.