{"id":1861,"date":"2026-07-17T23:28:11","date_gmt":"2026-07-17T23:28:11","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1861"},"modified":"2026-07-17T23:28:11","modified_gmt":"2026-07-17T23:28:11","slug":"new-goserpent-malware-targets-southeast-asian-governments-and-diplomats-for-espionage","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1861","title":{"rendered":"New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 17, 2026<\/span><\/span><span class=\"p-tags\">Cyber Espionage \/ Threat Intelligence<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgzr3TN2Kp4PBOBbzsR0RkNNu6_pMaYw05DjwQIegOdSeuDW5SAivGHOy3Qznjx5KJUTuiPRqAJsTDpM1O94X_FuG2sXAjD84rgPHwGxp2tFuP53Dm8pd-9bInejjZY7wx1jLBWu_EikCQ4HACf6J5Ycc3-kiTVE6-83MtCDCsL71o-7sFema5tOIV4IcJm\/s1700-e365\/GoSerpent-malware.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have discovered a previously undocumented malware called <strong>GoSerpent<\/strong> that has been put to use in cyber attacks targeting entities in Southeast Asia since late 2025 with a focus on long-term access and intelligence gathering.<\/p>\n<p>Russian cybersecurity company Kaspersky, which uncovered the activity in February 2026, said it was aimed at government and diplomatic entities in the region. GoSerpent is designed to contact an external server and deploy secondary payloads on sensitive data collection and credential dumping on the system.<\/p>\n<p>\u00abMonitoring the activities of this threat actor revealed that in May 2026 they came back with an evolved set of malicious tools: new Stowaway RAT and proxy tool which resembled the initial malware as well as an additional stealthy tool to exfiltrate sensitive data collected for the previous few months through network share,\u00bb security researcher Noushin Shabab <a href=\"https:\/\/securelist.com\/goserpent-backdoor-in-southeast-asia\/120687\/\" target=\"_blank\">said<\/a>.<\/p>\n<p>The end goal of these efforts is to harvest sensitive files and stage them for subsequent exfiltration using a data collecting tool dubbed ThumbcacheService. The attacks have also employed credential dumping tools via GoSerpent to capture system credentials need to facilitate data exfiltration through network shared drives.<\/p>\n<p>Earlier iterations of the Go-based implant and remote access trojan (RAT) have been put to use since 2021 against victims in Southeast Asia, with recent variants deployed as recently as this year.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The malware functions by receiving encrypted and Base64-encoded command-line arguments containing the command-and-control (C2) address and communication password. Once decrypted, the backdoor connects to the C2 server over an encrypted connection, where the SHA256 hash of the communication password serves as the encryption key.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>The list of supported commands is listed below &#8211;<\/p>\n<ul>\n<li>To alert the server of an active infection<\/li>\n<li>Start listening on a specific port<\/li>\n<li>Close a listening port<\/li>\n<li>Connect to a remote server<\/li>\n<li>Spawn a shell on the infected machine<\/li>\n<li>Upload a file or directory to the server<\/li>\n<li>Download from the server<\/li>\n<li>Start a SOCKS5 proxy on the infected machine<\/li>\n<li>Forward to a connected node<\/li>\n<\/ul>\n<p>\u00abGoSerpent can establish SOCKS5 proxy servers to route traffic through compromised hosts, enabling attackers to access other networks while masking their true IP addresses,\u00bb Kaspersky explained. \u00abThe backdoor is capable of deploying additional malicious tools, including ThumbcacheService for file collection, Mimikatz for credential dumping, and QuarksDumpLocalHash for local account password hash extraction.\u00bb<\/p>\n<p>Some of the other tools deployed over the course of the attacks are as follows &#8211;<\/p>\n<ul>\n<li><strong>McMx RAT<\/strong>, a basic Go-based proxy and remote access tool that&#8217;s a lightweight version of GoSerpent with capabilities such as SOCKS5 proxying, port forwarding, file transfer, and remote shell<\/li>\n<li><strong>ThumbcacheService<\/strong>, a DLL that supplements GoSerpent with a sophisticated file collection mechanism<\/li>\n<li><strong>Mimikatz<\/strong>, to dump memory from the Local Security Authority Subsystem Service (LSASS) process to extract credential material<\/li>\n<li><strong>QuarksDumpLocalHash<\/strong>, to extract local account password hashes from the SAM registry hive<\/li>\n<\/ul>\n<p>After months of covert data harvesting, the threat actors behind the activity are said to have returned to the compromised environment in May 2026 to deploy another set of tools &#8211;<\/p>\n<ul>\n<li><strong>Stowaway<\/strong>, a proxy and remote access tool with SOCKS5 proxying, port forwarding, reverse tunneling, remote shell access, file transfer, and SSH-based tunneling features<\/li>\n<li><strong>TmcLoader<\/strong>, a C++ loader module that contains an encrypted payload dubbed TmcPayload<\/li>\n<li><strong>TmcPayload<\/strong>, to exfiltrate stored sensitive data from the victim&#8217;s machine<\/li>\n<\/ul>\n<p>\u00abWhat makes this threat particularly concerning is the strategic deployment of various tools with sophisticated data collection and exfiltration capabilities,\u00bb Kaspersky said. \u00abThe chain from ThumbcacheService to TmcLoader\/TmcPayload demonstrates sophisticated operational planning.\u00bb<\/p>\n<p>Although definitive attribution remains cloudy at best, the security vendor said the campaign shares targeting, technical capabilities, and operational overlaps with <a href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/kaspersky-uncovers-apt-campaign-targeting-apac-government-entities\" target=\"_blank\">TetrisPhantom<\/a>, a \u00abhighly skilled and resourceful threat actor\u00bb it first <a href=\"https:\/\/securelist.com\/apt-trends-report-q3-2023\/110752\/\" target=\"_blank\">documented<\/a> in October 2023 as <a href=\"https:\/\/www.virusbulletin.com\/uploads\/pdf\/conference\/vb2023\/papers\/TetrisPhantom-targeted-attacks-using-secure-USB.pdf\" target=\"_blank\">targeting<\/a> government entities in the Asia-Pacific (APAC) region.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/sygnia-cyber-response-d-1\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiBxLQDy7VdLze43eMmpRllTXaPKPfB_veNUxQlqIu3-68GBJtegkhDGCqtaiSymOQviROdxln1FSd4zdMp5Jv9jeF1xQxLPc9uo9H7zW2nWHNax0wT0Y8JRj-zyUfbaCLqhxSfQT2sCfhWMBPL6UVgsh5RYVNVxwus_mW_BY9Ptwz3z7iF0_LWOnte-gqg\/s1600\/sy-d-1.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThe attacker covertly spied on and harvested sensitive data from APAC government entities by exploiting a particular type of secure USB drive, protected by hardware encryption to ensure the secure storage and transfer of data between computer systems,\u00bb the company noted at the time.<\/p>\n<p>\u00abThe campaign comprises various malicious modules, through which the actor can gain extensive control over the victim&#8217;s device. This allows them to execute commands, collect files and information from compromised machines, and transfer them to other machines using the same or different secure USB drives as carriers.\u00bb<\/p>\n<table cellpadding=\"0\" cellspacing=\"0\" class=\"tr-caption-container\" style=\"float: left;\">\n<tbody>\n<tr>\n<td style=\"text-align: center;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgmnxcS5E26tNn40kM2pySuG0LcFuL_qLuFuEziLOwU6ac39Q91JdOGQ5o-qXcPrNJH6WfVK208ijmHPPBgO1-mtvZQEEtLVqIs8NhIfwpopO6Jns9SrnbwJHCsyX0o5xP2eh8dLFZtlLtpwpmlSqxPBxJKbuFreloBfry-SWmat9Kskvoksyu8Lw7Bc6Hu\/s1700-e365\/howler.png\" style=\"clear: left; display: block; margin-left: auto; margin-right: auto;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgmnxcS5E26tNn40kM2pySuG0LcFuL_qLuFuEziLOwU6ac39Q91JdOGQ5o-qXcPrNJH6WfVK208ijmHPPBgO1-mtvZQEEtLVqIs8NhIfwpopO6Jns9SrnbwJHCsyX0o5xP2eh8dLFZtlLtpwpmlSqxPBxJKbuFreloBfry-SWmat9Kskvoksyu8Lw7Bc6Hu\/s1700-e365\/howler.png\" alt=\"\" border=\"0\" data-original-height=\"1319\" data-original-width=\"2228\"\/><\/a><\/td>\n<\/tr>\n<tr>\n<td class=\"tr-caption\" style=\"text-align: center;\">DoNot Team Attack Chain<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The disclosure comes as Cyderes Howler Cell detailed a targeted cyber espionage operation orchestrated by DoNot Team targeting Bangladesh&#8217;s military and defence establishments using spear-phishing emails containing a malware-laced RTF document to drop a DLL implant that sets up scheduled-task persistence disguised as OneDrive telemetry, profiles the host, and beacons to a C2 server over HTTPS.<\/p>\n<p>\u00abThe RTF uses remote template injection to fetch a VBA macro, with server-side geofencing restricting payload delivery to victims inside the target region,\u00bb researchers Reegun Jayapaul, Rahul Ramesh, and Baskar M <a href=\"https:\/\/www.cyderes.com\/howler-cell\/tracking-donot-apt-c-35-bangladesh-military-intrusion\" target=\"_blank\">said<\/a>. \u00abOnce the macro runs, it injects architecture-aware shellcode through callback-based API abuse. The shellcode moves through several XOR-encoded stages, each pulled from the same C2 domain under benign-looking file extensions.\u00bb<\/p>\n<p>The implant is then used to deliver a second-stage DLL (\u00abejtest.dll\u00bb), which features modular download capability for follow-on payloads. The attribution to DoNot Team is based on similar C2 URI paths, matching AES key material, VBA-based shellcode injection tradecraft, and geofenced payload delivery that serves clean templates to non-targets.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 17, 2026Cyber Espionage \/ Threat Intelligence Cybersecurity researchers have discovered a previously undocumented malware called GoSerpent that has been put to use in cyber attacks targeting entities in&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1862,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[100,2614,691,2613,378,42,593,78],"class_list":["post-1861","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-asian","tag-diplomats","tag-espionage","tag-goserpent","tag-governments","tag-malware","tag-southeast","tag-targets"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1861","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1861"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1861\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1862"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1861"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1861"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1861"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}