Kaspersky researchers have uncovered a patient cyber-espionage campaign targeting government and diplomatic entities in Southeast Asia, using new malware dubbed GoSerpent to harvest highly sensitive data over extended periods.
Identified in July 2026 by the company’s Global Research and Analysis Team (GReAT), the campaign relies on a set of customised tools — including the GoSerpent backdoor, Stowaway and TmcLoader — reflecting what researchers described as a high level of technical capability and operational planning.
A backdoor built for patience
At the centre of the campaign is the GoSerpent backdoor, a Go-based Remote Access Trojan (RAT) that has reportedly been active since at least 2021, with the latest known variant deployed in 2026. The malware incorporates strong persistence mechanisms and uses filenames that imitate legitimate system processes to reduce the likelihood of detection.
What sets the campaign apart is its deliberate dwell time, with secondary exfiltration tools deployed only weeks after the initial backdoor is planted — a tactic that makes it far harder for defenders to connect an initial infection to the eventual theft of data.
“What stands out about GoSerpent is the deliberate dwell time. Usually, attackers want to move quickly once they get a foothold, but this group drops the initial backdoor and waits. They let the dust settle for weeks before deploying their secondary exfiltration tools like TmcLoader. That kind of patience is a calculated move designed to outlast standard log retention policies and automated security sweeps, making it incredibly difficult for defenders to connect the initial infection to the eventual data theft.”
Noushin Shabab, Lead Security Researcher, Kaspersky GReAT
Possible link to known threat actor
Kaspersky’s researchers suspect a link between the GoSerpent campaign and the TetrisPhantom threat actor, based on shared victimology, technical capabilities and operational methods. While there are similarities, further investigation is ongoing before the campaign can be definitively attributed.
To reduce exposure, GReAT experts recommend that organisations remain vigilant against the indicators of compromise detailed in the report, and adopt security solutions that give government agencies fuller control over their data, support compliance with local regulations and strengthen the resilience of sovereign digital infrastructure. The full report is available on Kaspersky’s Securelist blog.



Share your thoughts