Kaspersky researchers have identified a sophisticated cyber espionage campaign dubbed GoSerpent, which targets government and diplomatic organizations across Southeast Asia using a custom-built remote access trojan (RAT) designed for long-term intelligence gathering and data theft.
Discovered in July 2026 by the company’s Global Research and Analysis Team (GReAT), the operation employs a toolkit that includes the GoSerpent backdoor, Stowaway, and TmcLoader, demonstrating a high level of technical sophistication and operational planning.
At the center of the campaign is the GoSerpent RAT, a malware strain written in the Go programming language that has reportedly been active since at least 2021. The latest variant, observed in 2026, uses advanced persistence techniques and disguises itself as legitimate system processes to evade detection and maintain access to compromised systems.
According to Kaspersky researchers, one of the campaign’s most notable characteristics is the attackers’ patience. Rather than immediately stealing data after gaining access, the threat actors reportedly establish a foothold and remain dormant for weeks before deploying secondary tools such as TmcLoader for data exfiltration.
Noushin Shabab, Lead Security Researcher at Kaspersky GReAT, said this extended dwell time allows attackers to outlast common log retention periods and evade routine security monitoring, making it significantly harder for defenders to connect the initial compromise to later data theft activities.
Kaspersky also noted potential links between the GoSerpent campaign and the TetrisPhantom threat actor. The assessment is based on similarities in targeted victims, technical capabilities, and operational tactics, although researchers said further investigation is needed before making a definitive attribution.
The discovery highlights the growing sophistication of cyber espionage operations targeting government institutions in the region. Advanced persistent threats (APTs) increasingly rely on stealth, persistence, and customized malware to maintain long-term access to sensitive networks and collect intelligence without triggering security alerts.
To defend against such threats, Kaspersky recommends that organizations closely monitor indicators of compromise (IoCs) associated with GoSerpent and deploy advanced security technologies such as Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), secure email protection, digital footprint monitoring, and managed threat detection services.
The company added that proactive threat hunting, incident response readiness, and continuous monitoring are essential for government agencies and critical organizations seeking to strengthen cyber resilience against evolving nation-state and espionage-related cyber threats.


