A cyber-espionage group has targeted government and diplomatic organizations in Southeast Asia using a coordinated set of malware designed to collect documents, steal credentials and remain undetected for extended periods, according to cybersecurity firm Kaspersky.
Kaspersky’s Global Research and Analysis Team said it discovered the malicious activity in February 2026, although the attacks had been underway since late 2025.
Researchers also found earlier versions of the campaign’s primary backdoor, dubbed GoSerpent, dating to 2021.
The company did not identify the countries or organizations affected by the campaign.
GoSerpent is a remote access Trojan written in the Go programming language. It allows attackers to open a remote command shell, upload and download files, forward network traffic and establish SOCKS5 proxy servers through compromised computers.
The proxy function can be used to reach other systems inside a victim’s network while concealing the attackers’ actual IP addresses.
The latest GoSerpent variant also encrypts its command-line configuration and communications with its command-and-control servers.
The malware maintains access to infected computers and uses filenames resembling legitimate system processes, including “lass.exe” and “updates.exe,” to avoid detection.
Instead of immediately stealing data, the attackers deploy additional tools and allow them to operate for weeks. One component, called ThumbcacheService, searches for Word documents, PDFs and Excel spreadsheets, including deleted files stored in the Windows recycle bin.
The collected files are compressed into password-protected archives limited to 20 megabytes each and stored on the compromised computer for later extraction.
GoSerpent also deploys credential-stealing tools, including Mimikatz and QuarksDumpLocalHash. These tools can extract cached credentials, Kerberos tickets and local account password hashes that may allow attackers to access other systems or network drives.
“What stands out about GoSerpent is the deliberate dwell time. Usually, attackers want to move quickly once they get a foothold, but this group drops the initial backdoor and waits. They let the dust settle for weeks before deploying their secondary exfiltration tools like TmcLoader,” said Noushin Shabab, lead security researcher at Kaspersky’s Global Research and Analysis Team
“That kind of patience is a calculated move designed to outlast standard log retention policies and automated security sweeps, making it incredibly difficult for defenders to connect the initial infection to the eventual data theft.”
Kaspersky said the attackers returned in May 2026 with another Go-based remote access and proxy tool called Stowaway.
The customized tool supports port forwarding, reverse tunneling, remote shell access, file transfers and SSH-based tunneling.
Stowaway was used to install TmcLoader and its embedded payload, which completed the data-theft process. TmcLoader operates as a Windows service and loads the payload into the memory of the legitimate Windows “svchost” process to maintain access and make detection more difficult.
The payload reads an encrypted configuration file containing stolen network credentials and the destination paths for the collected data. It then transfers the archive created by ThumbcacheService through network shares.
Kaspersky said the way the components work together indicates that the operation was planned as a multistage intelligence-gathering campaign rather than a quick data grab.
The attackers also used infrastructure hosted by legitimate providers, including Alibaba Cloud and UCLOUD HK, for command-and-control communications.
Kaspersky said similarities in the campaign’s targets, tools and operating methods point to a possible connection with the TetrisPhantom threat actor. However, the company said further investigation was needed before the campaign could be definitively attributed.


