The GoSerpent campaign is a sophisticated cyberespionage operation active since late 2025, primarily targeting government and diplomatic entities in Southeast Asia. The attack chain utilizes a multi-stage approach, beginning with the GoSerpent backdoor—a Go-based RAT capable of SOCKS5 proxying, port forwarding, and shell access. This initial phase focuses on data collection using the ThumbcacheService DLL and credential harvesting via tools like Mimikatz, setting the stage for long-term intelligence gathering.
In later stages, the threat actor deploys evolved tools including the Stowaway proxy framework and the TmcLoader/TmcPayload module. These components work in tandem to exfiltrate collected archives through network shares using stolen credentials. The integration between collection, credential theft, and stealthy exfiltration demonstrates high operational planning. Infrastructure analysis shows a reliance on legitimate hosting providers like Alibaba Cloud, and some technical overlaps suggest a potential link to the TetrisPhantom threat group.
Top comments (0)