Threat reportMalwareTL-2026-1415

GoSerpent Backdoor Campaign Targets Southeast Asian Government and Diplomatic Entities

highACTIVE

GoSerpent Backdoor Campaign Targets Southeast Asian (TL-2026-1415), also tracked as GoSerpent Campaign, is a high-severity malware campaign, first published 2026-07-16. It is attributed to TetrisPhantom with low confidence, affects Microsoft Windows, maps to 24 MITRE ATT&CK techniques (T1003, T1005, T1016), and is covered by 9 detection rules and 44 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
24MITRE ATT&CK
Actors
1TetrisPhantom
Detection rules
9SPL · KQL · Sigma
IOCs
44Indicators of compromise

Key facts for TL-2026-1415

Threat ID
TL-2026-1415
Also known as
GoSerpent Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
TetrisPhantom
Attribution confidence
LOW
Motivation
ESPIONAGE
Target sectors
government administration, diplomatic
Target regions
Southeast Asia, Asia-Pacific
Detection rules
9
Indicators of compromise
44

Malware and tooling in GoSerpent Backdoor Campaign Targets Southeast Asian

Malware and tooling: GoSerpent, McMx RAT, STOWAWAY, ThumbcacheService, TmcLoader, TmcPayload, Mimikatz, QuarksDumpLocalHash

How GoSerpent Backdoor Campaign Targets Southeast Asian works

A multi-stage intrusion set uses the Go-based GoSerpent backdoor alongside McMx RAT, ThumbcacheService, and Stowaway/TmcLoader to compromise government and diplomatic entities in Southeast Asia, chaining credential dumping, targeted file collection, and encrypted exfiltration. Possible connection to the TetrisPhantom APT cluster, though attribution remains uncertain.

Kaspersky's GReAT team documented a persistent, evolving intrusion set — tracked internally as the GoSerpent campaign — active against government and diplomatic entities across Southeast Asia. The operation unfolds in two observed phases. In the first (late 2025), operators deployed GoSerpent, a Go-based RAT/backdoor active since 2021 that communicates over an AES-CBC (fixed IV) and ChaCha20-encrypted channel, alongside ThumbcacheService, a DLL/service-based file-collection tool that stages data locally using single-byte XOR obfuscation (key 0x13). During this phase the operators also deployed the credential-dumping tools Mimikatz (LSASS memory dumping for cached credentials and Kerberos tickets) and QuarksDumpLocalHash (SAM registry hive extraction for offline password cracking) over a multi-week collection window. In the second observed phase (May 2026), the operators introduced Stowaway, an open-source-framework-derived RAT/SOCKS5 proxy tool using AES-256-GCM over TLS, and a two-stage C++ loader/payload pair (TmcLoader/TmcPayload) that uses circular-XOR-plus-Base64 obfuscation to protect an embedded configuration file (written to a path derived from an obfuscated string, e.g. C:\Users\Public\Libraries\{BBF061R2-BE25-4F6D-8B2D-1A6A39C3FSA2}.db) and exfiltrates staged data over network shares using harvested credentials. Persistence is achieved via Windows service registration (ThumbcacheService, TmcLoader) and filenames that mimic legitimate system processes (e.g. lass.exe, updates.exe); a unique-event check prevents multiple concurrent infections on the same host. Secret keys embedded in the malware configurations reuse legitimate domain strings (microsoft.com, spacex.com, github.code) as part of a standardized operational tradecraft pattern across the toolset. C2 infrastructure is hosted on Alibaba Cloud and UCLOUD HK across eleven identified IP addresses. Kaspersky notes technical and targeting similarities to TetrisPhantom, a previously catalogued APAC-focused espionage cluster first exposed in 2023 for compromising secure, hardware-encrypted USB drives used by Southeast Asian government agencies via SCSI-level firmware tampering, and which has since expanded its toolset with BoostPlug and DeviceCync (a loader for ShadowPad, PhantomNet, and Ghost RAT) — but attribution of the GoSerpent campaign to TetrisPhantom is not confirmed.

MITRE ATT&CK techniques used in TL-2026-1415

Credential Access

T1003 OS Credential Dumping

Collection

T1005 Data from Local System; T1074 Data Staged; T1119 Automated Collection; T1560 Archive Collected Data

Discovery

T1016 System Network Configuration Discovery; T1135 Network Share Discovery

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1140 Deobfuscate/Decode Files or Information

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Privilege Escalation

T1055 Process Injection

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1219 Remote Access Tools; T1571 Non-Standard Port; T1573 Encrypted Channel

Initial Access

T1078 Valid Accounts

Persistence

T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

Execution

T1569 System Services

Resource Development

T1583 Acquire Infrastructure

Affected products and versions in GoSerpent Backdoor Campaign Targets Southeast Asian

  • Microsoft — Windows
    Vulnerable versions: All supported versions targeted via service-based persistence

Remediation for GoSerpent Backdoor Campaign Targets Southeast Asian

Immediate actions

  • Block all 11 identified C2 IP addresses at perimeter firewalls and proxies
  • Hunt for the 12 published file hashes across EDR/AV telemetry
  • Hunt for processes named lass.exe, updates.exe, or unexpected services named ThumbcacheService / TmcLoader
  • Audit for the TmcPayload configuration artifact path C:\Users\Public\Libraries\{BBF061R2-BE25-4F6D-8B2D-1A6A39C3FSA2}.db
  • Reset credentials and force Kerberos ticket invalidation for any host where Mimikatz or QuarksDumpLocalHash activity is suspected
  • Review network share access logs for anomalous bulk file transfers to external destinations

Workarounds

  • Restrict outbound network-share (SMB) access to only trusted internal destinations
  • Enable PowerShell/command-line logging to detect encrypted-argument invocation patterns used by GoSerpent

Longer-term hardening

  • Deploy EDR with behavioral detection for LSASS access and SAM hive reads
  • Segment government/diplomatic networks to limit lateral movement via SOCKS5 proxies (Stowaway)
  • Implement egress filtering and TLS inspection for outbound connections to Alibaba Cloud / UCLOUD HK ASN ranges
  • Deploy application allowlisting to prevent execution of unsigned service binaries mimicking system process names
  • Harden credential storage (Credential Guard, LSA Protection) to blunt Mimikatz-class dumping tools

Weaknesses (CWE) in GoSerpent Backdoor Campaign Targets Southeast Asian

CWE-522, CWE-311, CWE-506

Timeline of GoSerpent Backdoor Campaign Targets Southeast Asian

  • Earlier versions of the GoSerpent Go-based backdoor first observed active against victims in Southeast Asia, per Kaspersky's toolset dating.
  • Kaspersky GReAT first publicly discloses the TetrisPhantom espionage cluster targeting APAC government entities via compromised secure USB drives.
  • Kaspersky's Q3 2024 APT trends report documents TetrisPhantom's toolset expansion with BoostPlug and DeviceCync, a loader used to deploy ShadowPad, PhantomNet, and Ghost RAT — cited by Kaspersky as prior context when weighing a possible GoSerpent/TetrisPhantom overlap.
  • Phase 1 of the GoSerpent campaign begins (late 2025): GoSerpent backdoor and ThumbcacheService file-collection tool deployed against Southeast Asian government/diplomatic targets, with Mimikatz and QuarksDumpLocalHash used for credential dumping over a multi-week collection window; ThumbcacheService stages stolen files locally as thumbcache_605a.db under C:\Users\Public\ and monitors the $Recycle.Bin directory for deleted files.
  • Kaspersky GReAT discovers the malicious GoSerpent-related activity during incident response/telemetry review, per the Securelist report's disclosed discovery timeframe.
  • Phase 2 observed: the threat actor returns with an evolved toolset, introducing the Stowaway RAT/SOCKS5 proxy tool (AES-256-GCM/TLS) and the TmcLoader/TmcPayload two-stage C++ loader pair, exfiltrating staged data over network shares using harvested credentials; stolen data is archived into password-protected 7-Zip files (password @vx0a9n5W2M0c3D6.#) capped at 20MB per archive before exfiltration.
  • TL-Intel Harness ingests the Securelist report via RSS hunt phase and opens threat TL-2026-1415.
  • Kaspersky Securelist publishes the full technical report 'GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration,' including 20 file hashes and 11 C2 IP addresses, and notes possible TetrisPhantom overlap.

Sources cited for GoSerpent Backdoor Campaign Targets Southeast Asian

Detection coverage for TL-2026-1415

As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1415 across Splunk SPL, Microsoft KQL and Sigma, covering 44 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
44 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats