# GoSerpent Backdoor Campaign Targets Southeast Asian Government and Diplomatic Entities

> A multi-stage intrusion set uses the Go-based GoSerpent backdoor alongside McMx RAT, ThumbcacheService, and Stowaway/TmcLoader to compromise government and diplomatic entities in Southeast Asia, chaining credential dumping, targeted file collection, and encrypted exfiltration. Possible connection to the TetrisPhantom APT cluster, though attribution remains uncertain.

- **Published:** 2026-07-16T00:00:00Z
- **Last reviewed:** 2026-07-16T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1415
- **ID:** TL-2026-1415
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** TetrisPhantom
- **Detections:** 9 · **IOCs:** 44 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Kaspersky's GReAT team documented a persistent, evolving intrusion set — tracked internally as the GoSerpent campaign — active against government and diplomatic entities across Southeast Asia. The operation unfolds in two observed phases. In the first (late 2025), operators deployed GoSerpent, a Go-based RAT/backdoor active since 2021 that communicates over an AES-CBC (fixed IV) and ChaCha20-encrypted channel, alongside ThumbcacheService, a DLL/service-based file-collection tool that stages data locally using single-byte XOR obfuscation (key 0x13). During this phase the operators also deployed the credential-dumping tools Mimikatz (LSASS memory dumping for cached credentials and Kerberos tickets) and QuarksDumpLocalHash (SAM registry hive extraction for offline password cracking) over a multi-week collection window. In the second observed phase (May 2026), the operators introduced Stowaway, an open-source-framework-derived RAT/SOCKS5 proxy tool using AES-256-GCM over TLS, and a two-stage C++ loader/payload pair (TmcLoader/TmcPayload) that uses circular-XOR-plus-Base64 obfuscation to protect an embedded configuration file (written to a path derived from an obfuscated string, e.g. C:\Users\Public\Libraries\{BBF061R2-BE25-4F6D-8B2D-1A6A39C3FSA2}.db) and exfiltrates staged data over network shares using harvested credentials. Persistence is achieved via Windows service registration (ThumbcacheService, TmcLoader) and filenames that mimic legitimate system processes (e.g. lass.exe, updates.exe); a unique-event check prevents multiple concurrent infections on the same host. Secret keys embedded in the malware configurations reuse legitimate domain strings (microsoft.com, spacex.com, github.code) as part of a standardized operational tradecraft pattern across the toolset. C2 infrastructure is hosted on Alibaba Cloud and UCLOUD HK across eleven identified IP addresses. Kaspersky notes technical and targeting similarities to TetrisPhantom, a previously catalogued APAC-focused espionage cluster first exposed in 2023 for compromising secure, hardware-encrypted USB drives used by Southeast Asian government agencies via SCSI-level firmware tampering, and which has since expanded its toolset with BoostPlug and DeviceCync (a loader for ShadowPad, PhantomNet, and Ghost RAT) — but attribution of the GoSerpent campaign to TetrisPhantom is not confirmed.

## MITRE ATT&CK

- T1078 Valid Accounts
- T1569 System Services
- T1543 Create or Modify System Process
- T1547 Boot or Logon Autostart Execution
- T1055 Process Injection
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1003 OS Credential Dumping
- T1016 System Network Configuration Discovery
- T1135 Network Share Discovery
- T1021 Remote Services
- T1074 Data Staged
- T1119 Automated Collection
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1090 Proxy
- T1219 Remote Access Tools
- T1571 Non-Standard Port
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1583 Acquire Infrastructure
- T1560 Archive Collected Data
- T1005 Data from Local System

## Sources

- [GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration](https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/)
- [New TetrisPhantom hackers steal data from secure USB drives on govt systems](https://www.bleepingcomputer.com/news/security/new-tetrisphantom-hackers-steal-data-from-secure-usb-drives-on-govt-systems/)
- [Kaspersky uncovers APT campaign targeting APAC government entities](https://www.kaspersky.com/about/press-releases/kaspersky-uncovers-apt-campaign-targeting-apac-government-entities)
- [A new attack on secure USB drives: Kaspersky reveals key trends in the Q3 APT report](https://www.kaspersky.com/about/press-releases/a-new-attack-on-secure-usb-drives-kaspersky-reveals-key-trends-in-the-q3-apt-report)
- [Kaspersky report on APT trends in Q3 2024](https://securelist.com/apt-report-q3-2024/114623/)
- [TetrisPhantom targets government entities in APAC, Kaspersky warns](https://futurecio.tech/tetrisphantom-targets-government-entities-in-apac-kaspersky-warns/)
- [Persistent Espionage Campaign Targets APAC Governments](https://www.infosecurity-magazine.com/news/espionage-campaign-targets-apac/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1415
