
Kaspersky researchers say they have uncovered a long-running cyber-espionage campaign targeting government and diplomatic organisations in Southeast Asia, using a Go-based remote access trojan designed less for smash-and-grab theft than for patient intelligence collection.
The campaign, which Kaspersky’s Global Research and Analysis Team has dubbed GoSerpent, was identified in July 2026. According to the company, the operation uses a customised toolset that includes the GoSerpent backdoor, Stowaway, and TmcLoader, suggesting a campaign built for persistence, stealth, and staged data exfiltration.
Also Read: After cyber attacks, silence can be the biggest brand killer: Penta’s Dan La Russo
The finding lands in a region where state-linked cyber operations have become part of the wider geopolitical weather. Southeast Asia sits between major powers, hosts critical shipping lanes, has a dense web of diplomatic missions, and is rapidly digitising public services. For attackers seeking policy intelligence, trade positions, defence information, or diplomatic cables, ministries and embassies in the region are high-value targets.
A campaign built around patience
Kaspersky described GoSerpent as a sophisticated remote access trojan that has been active since at least 2021, with the latest known variant deployed this year. Written in Go, the malware uses persistence mechanisms and filenames that mimic legitimate system processes, a familiar but effective trick to reduce visibility inside compromised systems.
What makes this campaign notable is not just the tooling but the tempo. Rather than immediately deploying every payload after gaining access, the attackers appear to wait before moving to secondary tools used for exfiltration.
“What stands out about GoSerpent is the deliberate dwell time. Usually, attackers want to move quickly once they get a foothold, but this group drops the initial backdoor and waits,” said Noushin Shabab, Lead Security Researcher in Kaspersky GReAT. “They let the dust settle for weeks before deploying their secondary exfiltration tools like TmcLoader.”
That delay, she added, is designed to outlast standard log retention policies and automated security sweeps, making it harder for defenders to connect the first compromise with the later theft of data.
For under-resourced government agencies, this is a serious problem. Many public-sector systems in the region still run on uneven security budgets, fragmented vendor environments, and legacy infrastructure. Even where agencies have endpoint protection and monitoring in place, long dwell times can expose gaps in logging, incident response, and cross-agency threat sharing.
Why Southeast Asia remains a prime target
Kaspersky said the victims were government and diplomatic entities in Southeast Asia, though it did not name specific countries or agencies. That omission is typical in cyber-espionage reporting, where disclosing victims may trigger diplomatic fallout or reveal ongoing investigations.
The regional context matters. ASEAN has placed cybersecurity on the policy agenda through efforts such as the ASEAN Cybersecurity Cooperation Strategy 2021-2025 and the ASEAN-Singapore Cybersecurity Centre of Excellence. Singapore, Malaysia, Thailand, Indonesia, Vietnam, and the Philippines have all expanded national cyber agencies or regulations in recent years. Yet the region remains uneven: Singapore has mature cyber governance, while several neighbours continue to grapple with shortages of skilled personnel, decentralised IT procurement, and weak incident disclosure cultures.
Also Read: Hackers using AI to mask identity behind cyber attacks, researchers say
That unevenness gives advanced threat actors room to operate. A compromised diplomatic network in one country can become a stepping stone to broader intelligence on ASEAN negotiations, defence partnerships, trade deals, maritime disputes, or foreign investment decisions. In the context of the South China Sea, supply-chain realignments, semiconductor policy, and digital trade rules, diplomatic inboxes and internal files are not mere administrative targets; they are intelligence assets.
For Southeast Asia’s startup ecosystem, the lesson is indirect but important. Govtech vendors, cloud service providers, cybersecurity startups, system integrators, and managed service providers increasingly sit inside public-sector supply chains. Attackers do not always need to breach a ministry head-on if a contractor with weaker controls offers a cleaner route in.
Possible link to TetrisPhantom
Kaspersky said it suspects a connection between GoSerpent and the TetrisPhantom threat actor, citing overlaps in victimology, technical capabilities, and operational methods. The company has not made a definitive attribution and said further investigation is continuing.
TetrisPhantom has previously been associated with cyber-espionage activity against government entities in Asia-Pacific, including campaigns that drew attention because of their focus on highly specific targets and operational discipline. A possible link, if eventually confirmed, would reinforce the view that GoSerpent is not a commodity malware campaign but part of a more targeted intelligence operation.
Attribution in cyber-espionage remains a messy business. Security vendors typically rely on infrastructure overlaps, malware similarities, victim profiles, operational timing, and tradecraft. None of these alone is conclusive. Groups also reuse tools, borrow techniques, and deliberately plant false flags. Kaspersky’s cautious wording is therefore notable: the company is flagging similarities without declaring a firm actor behind the campaign.
Beyond tools: the hard part is visibility
Kaspersky’s advisory urges organisations to watch for GoSerpent indicators of compromise and strengthen detection, response, email security, digital footprint monitoring, compromise assessments, and incident response readiness. Stripped of the product language, the underlying point is straightforward: agencies need better telemetry and longer memory.
A campaign that waits weeks between initial access and exfiltration is betting that defenders will lose the trail. Short log-retention windows, siloed security teams, and over-reliance on automated alerts all work in the attacker’s favour. For diplomatic and government networks, where the data value is high and intrusions may be quiet, security teams need the ability to reconstruct events across endpoints, servers, identity systems, and email environments over extended periods.
Also Read: Are cyber attacks more life-threatening than we think?
The GoSerpent disclosure is not a mass-market ransomware story. There is no public claim site, no splashy ransom note, and no immediate operational shutdown. That makes it less visible but arguably more consequential. In espionage campaigns, success is measured by what remains unknown: how long the attacker stayed, what they read, and which decisions they influenced before anyone noticed.
The post GoSerpent exposes the quiet cyber war against Southeast Asian governments appeared first on e27.
