Kaspersky researchers have published detailed findings on GoSerpent, a previously undocumented Go-based backdoor that has been conducting long-term espionage operations against government and diplomatic entities across Southeast Asia since at least late 2025. The implant was first identified in February 2026, and by May 2026 the threat actor had evolved their toolset significantly — introducing new Stowaway RAT and proxy modules alongside a stealthy data exfiltration method that aggregates collected intelligence over weeks through internal network shares before moving it outside.

GoSerpent’s capabilities include establishing SOCKS5 proxy servers to route traffic through compromised hosts, deploying ThumbcacheService for file collection, Mimikatz for credential dumping, and QuarksDumpLocalHash for local account hash extraction. The implant receives encrypted and Base64-encoded command-line arguments containing C2 addresses and communication passwords, making passive traffic analysis significantly harder. The focus on intelligence gathering over disruption, combined with the slow exfiltration method, suggests a nation-state-aligned adversary prioritizing deniability and persistence over speed.

Source

Commentary

GoSerpent is a textbook example of a quiet, patient APT operation. The choice of Go as the implementation language is notable — Go-based implants are increasingly favored for their cross-platform support, relatively small runtime footprint, and resistance to static analysis compared to C/C++ or .NET. The slow exfiltration pattern (collecting data over months via network shares before egress) is specifically designed to fly under data-loss-prevention radar, making behavior-based detection the only reliable countermeasure.

For governments and diplomatic institutions in Southeast Asia — particularly those involved in regional security, infrastructure planning, or negotiations with major powers — GoSerpent represents an ongoing, likely active threat. The Stowaway RAT additions in May 2026 suggest the operator is actively investing in the toolset, making attribution and disruption increasingly difficult.

By Allan