Skip to main content

Kaspersky uncovers a patient cyber-espionage campaign using new GoSerpent malware to harvest diplomatic secrets

July 16, 2026

The new GoSerpent RAT targeted government and diplomatic entities in Southeast Asia. The campaign underscores the threat actor’s emphasis on maintaining long-term access and conducting intelligence collection.

In July 2026, researchers from the Kaspersky Global Research and Analysis Team (GReAT) team identified a new campaign, dubbed GoSerpent, representing a sophisticated and adaptive threat focused on the collection and exfiltration of sensitive data. According to the researchers, the operation relies on a set of customized tools, including the GoSerpent backdoor, Stowaway, and TmcLoader, reflecting a high level of technical capability and operational planning.

A central component of the campaign is the GoSerpent backdoor, a sophisticated Go-based Remote Access Trojan (RAT) that has reportedly been active since at least 2021, with the latest known variant deployed in 2026. The malware incorporates strong persistence mechanisms and uses filenames that imitate legitimate system processes to reduce the likelihood of detection.

“What stands out about GoSerpent is the deliberate dwell time. Usually, attackers want to move quickly once they get a foothold, but this group drops the initial backdoor and waits. They let the dust settle for weeks before deploying their secondary exfiltration tools like TmcLoader. That kind of patience is a calculated move designed to outlast standard log retention policies and automated security sweeps, making it incredibly difficult for defenders to connect the initial infection to the eventual data theft," — says Noushin Shabab, Lead Security Researcher in Kaspersky GReAT.

The company’s researchers suspect a link between the GoSerpent campaign and the TetrisPhantom threat actor based on shared victimology, technical capabilities, and operational methods. While there are similarities, further investigation is ongoing to definitively attribute the campaign.

The full report is available on securelist.com.

To stay safe, Kaspersky GReAT experts recommend organizations:

  • Remain highly vigilant against the deployment of GoSerpent IoCs and other tools presented in the report.

  • Apply cybersecurity solutions that enable government agencies worldwide to regain full control over their data, ensure compliance with local regulations, and build resilient, sovereign digital infrastructures. Such options are provided by Kaspersky solutions like:

 

About the Global Research & Analysis Team

Established in 2008, Global Research & Analysis Team (GReAT) operates at the very heart of Kaspersky, uncovering APTs, cyber-espionage campaigns, major malware, ransomware and underground cyber-criminal trends across the world. Today GReAT consists of 35+ experts working globally – in Europe, Russia, Latin America, Asia and the Middle East. Talented security professionals provide company leadership in anti-malware research and innovation, bringing unrivaled expertise, passion and curiosity to the discovery and analysis of cyberthreats.

Kaspersky uncovers a patient cyber-espionage campaign using new GoSerpent malware to harvest diplomatic secrets

The new GoSerpent RAT targeted government and diplomatic entities in Southeast Asia. The campaign underscores the threat actor’s emphasis on maintaining long-term access and conducting intelligence collection.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases