Threat reportMalwareTL-2026-1415
GoSerpent Backdoor Campaign Targets Southeast Asian Government and Diplomatic Entities
GoSerpent Backdoor Campaign Targets Southeast Asian (TL-2026-1415), also tracked as GoSerpent Campaign, is a high-severity malware campaign, first published 2026-07-16. It is attributed to TetrisPhantom with low confidence, affects Microsoft Windows, maps to 24 MITRE ATT&CK techniques (T1003, T1005, T1016), and is covered by 9 detection rules and 44 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 24MITRE ATT&CK
- Actors
- 1TetrisPhantom
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 44Indicators of compromise
Key facts for TL-2026-1415
- Threat ID
- TL-2026-1415
- Also known as
- GoSerpent Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- TetrisPhantom
- Attribution confidence
- LOW
- Motivation
- ESPIONAGE
- Target sectors
- government administration, diplomatic
- Target regions
- Southeast Asia, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 44
Malware and tooling in GoSerpent Backdoor Campaign Targets Southeast Asian
Malware and tooling: GoSerpent, McMx RAT, STOWAWAY, ThumbcacheService, TmcLoader, TmcPayload, Mimikatz, QuarksDumpLocalHash
How GoSerpent Backdoor Campaign Targets Southeast Asian works
A multi-stage intrusion set uses the Go-based GoSerpent backdoor alongside McMx RAT, ThumbcacheService, and Stowaway/TmcLoader to compromise government and diplomatic entities in Southeast Asia, chaining credential dumping, targeted file collection, and encrypted exfiltration. Possible connection to the TetrisPhantom APT cluster, though attribution remains uncertain.
Kaspersky's GReAT team documented a persistent, evolving intrusion set — tracked internally as the GoSerpent campaign — active against government and diplomatic entities across Southeast Asia. The operation unfolds in two observed phases. In the first (late 2025), operators deployed GoSerpent, a Go-based RAT/backdoor active since 2021 that communicates over an AES-CBC (fixed IV) and ChaCha20-encrypted channel, alongside ThumbcacheService, a DLL/service-based file-collection tool that stages data locally using single-byte XOR obfuscation (key 0x13). During this phase the operators also deployed the credential-dumping tools Mimikatz (LSASS memory dumping for cached credentials and Kerberos tickets) and QuarksDumpLocalHash (SAM registry hive extraction for offline password cracking) over a multi-week collection window. In the second observed phase (May 2026), the operators introduced Stowaway, an open-source-framework-derived RAT/SOCKS5 proxy tool using AES-256-GCM over TLS, and a two-stage C++ loader/payload pair (TmcLoader/TmcPayload) that uses circular-XOR-plus-Base64 obfuscation to protect an embedded configuration file (written to a path derived from an obfuscated string, e.g. C:\Users\Public\Libraries\{BBF061R2-BE25-4F6D-8B2D-1A6A39C3FSA2}.db) and exfiltrates staged data over network shares using harvested credentials. Persistence is achieved via Windows service registration (ThumbcacheService, TmcLoader) and filenames that mimic legitimate system processes (e.g. lass.exe, updates.exe); a unique-event check prevents multiple concurrent infections on the same host. Secret keys embedded in the malware configurations reuse legitimate domain strings (microsoft.com, spacex.com, github.code) as part of a standardized operational tradecraft pattern across the toolset. C2 infrastructure is hosted on Alibaba Cloud and UCLOUD HK across eleven identified IP addresses. Kaspersky notes technical and targeting similarities to TetrisPhantom, a previously catalogued APAC-focused espionage cluster first exposed in 2023 for compromising secure, hardware-encrypted USB drives used by Southeast Asian government agencies via SCSI-level firmware tampering, and which has since expanded its toolset with BoostPlug and DeviceCync (a loader for ShadowPad, PhantomNet, and Ghost RAT) — but attribution of the GoSerpent campaign to TetrisPhantom is not confirmed.
MITRE ATT&CK techniques used in TL-2026-1415
Credential Access
Collection
T1005 Data from Local System; T1074 Data Staged; T1119 Automated Collection; T1560 Archive Collected Data
Discovery
T1016 System Network Configuration Discovery; T1135 Network Share Discovery
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Privilege Escalation
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1219 Remote Access Tools; T1571 Non-Standard Port; T1573 Encrypted Channel
Initial Access
Persistence
T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
Execution
Resource Development
Affected products and versions in GoSerpent Backdoor Campaign Targets Southeast Asian
- Microsoft — Windows
Vulnerable versions: All supported versions targeted via service-based persistence
Remediation for GoSerpent Backdoor Campaign Targets Southeast Asian
Immediate actions
- Block all 11 identified C2 IP addresses at perimeter firewalls and proxies
- Hunt for the 12 published file hashes across EDR/AV telemetry
- Hunt for processes named lass.exe, updates.exe, or unexpected services named ThumbcacheService / TmcLoader
- Audit for the TmcPayload configuration artifact path C:\Users\Public\Libraries\{BBF061R2-BE25-4F6D-8B2D-1A6A39C3FSA2}.db
- Reset credentials and force Kerberos ticket invalidation for any host where Mimikatz or QuarksDumpLocalHash activity is suspected
- Review network share access logs for anomalous bulk file transfers to external destinations
Workarounds
- Restrict outbound network-share (SMB) access to only trusted internal destinations
- Enable PowerShell/command-line logging to detect encrypted-argument invocation patterns used by GoSerpent
Longer-term hardening
- Deploy EDR with behavioral detection for LSASS access and SAM hive reads
- Segment government/diplomatic networks to limit lateral movement via SOCKS5 proxies (Stowaway)
- Implement egress filtering and TLS inspection for outbound connections to Alibaba Cloud / UCLOUD HK ASN ranges
- Deploy application allowlisting to prevent execution of unsigned service binaries mimicking system process names
- Harden credential storage (Credential Guard, LSA Protection) to blunt Mimikatz-class dumping tools
Weaknesses (CWE) in GoSerpent Backdoor Campaign Targets Southeast Asian
Timeline of GoSerpent Backdoor Campaign Targets Southeast Asian
- Earlier versions of the GoSerpent Go-based backdoor first observed active against victims in Southeast Asia, per Kaspersky's toolset dating.
- Kaspersky GReAT first publicly discloses the TetrisPhantom espionage cluster targeting APAC government entities via compromised secure USB drives.
- Kaspersky's Q3 2024 APT trends report documents TetrisPhantom's toolset expansion with BoostPlug and DeviceCync, a loader used to deploy ShadowPad, PhantomNet, and Ghost RAT — cited by Kaspersky as prior context when weighing a possible GoSerpent/TetrisPhantom overlap.
- Phase 1 of the GoSerpent campaign begins (late 2025): GoSerpent backdoor and ThumbcacheService file-collection tool deployed against Southeast Asian government/diplomatic targets, with Mimikatz and QuarksDumpLocalHash used for credential dumping over a multi-week collection window; ThumbcacheService stages stolen files locally as thumbcache_605a.db under C:\Users\Public\ and monitors the $Recycle.Bin directory for deleted files.
- Kaspersky GReAT discovers the malicious GoSerpent-related activity during incident response/telemetry review, per the Securelist report's disclosed discovery timeframe.
- Phase 2 observed: the threat actor returns with an evolved toolset, introducing the Stowaway RAT/SOCKS5 proxy tool (AES-256-GCM/TLS) and the TmcLoader/TmcPayload two-stage C++ loader pair, exfiltrating staged data over network shares using harvested credentials; stolen data is archived into password-protected 7-Zip files (password @vx0a9n5W2M0c3D6.#) capped at 20MB per archive before exfiltration.
- TL-Intel Harness ingests the Securelist report via RSS hunt phase and opens threat TL-2026-1415.
- Kaspersky Securelist publishes the full technical report 'GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration,' including 20 file hashes and 11 C2 IP addresses, and notes possible TetrisPhantom overlap.
Sources cited for GoSerpent Backdoor Campaign Targets Southeast Asian
- GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
- New TetrisPhantom hackers steal data from secure USB drives on govt systems
- Kaspersky uncovers APT campaign targeting APAC government entities
- A new attack on secure USB drives: Kaspersky reveals key trends in the Q3 APT report
- Kaspersky report on APT trends in Q3 2024
- TetrisPhantom targets government entities in APAC, Kaspersky warns
- Persistent Espionage Campaign Targets APAC Governments
Detection coverage for TL-2026-1415
As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1415 across Splunk SPL, Microsoft KQL and Sigma, covering 44 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.