Back to Intel

Intel Node

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

lowapt2026-07-16T12:00:27+00:00source excerpt
aptmalware

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.

Introduction In February 2026, we discovered a set of malicious activities that had been ongoing since late 2025. These activities involved a RAT module written in Go with proxy capabilities, which served as the main stage of the attack. The attack targeted government and diplomatic entities in Southeast Asia and showed a level of sophistication that caught our attention. During the attack, the main malware, dubbed GoSerpent, received an encrypted argument and started communicating with a remote server. It was also used to deploy further malicious tools to collect sensitive data and dump credentials on the system.

Read Original Source