Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators GoSerpent backdoor attacks in Southeast Asia

ebffd5a76aaa690bcdb922f82e0bacc5

TLP:CLEAR
Active

MD5 Hash

Description

Since late 2025, government and diplomatic entities in Southeast Asia have been targeted by sophisticated attacks involving GoSerpent, a Go-based RAT with proxy capabilities. The malware receives encrypted arguments and deploys additional tools for data collection and credential dumping. GoSerpent has been active since 2021, with newer variants using AES-CBC encryption and ChaCha20 for communications. The campaign involves multiple stages: initial deployment of GoSerpent and ThumbcacheService to collect sensitive files, credential dumping via Mimikatz and QuarksDumpLocalHash, followed by deployment of Stowaway RAT in May 2026 and TmcLoader/TmcPayload for stealthy data exfiltration through network shares. The integrated toolset demonstrates sophisticated operational planning, with attackers leveraging Alibaba Cloud and UCLOUD HK infrastructure while exhibiting possible connections to the TetrisPhantom threat actor.

Sightings (0)

No sightings recorded yet

Details

Name / Label
GoSerpent backdoor attacks in Southeast Asia
Pattern Type
STIX
Confidence
75%
Valid From
Jul 17, 2026 02:00
Total Sightings
0
Added
Jul 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of ebffd5a76aaa690bcdb922f82e0bacc5

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.