KASPERSKY'S GReAT team reported on July 16, 2026, about the GoSerpent backdoor, a long-running cyber espionage campaign targeting government and diplomatic networks in Southeast Asia since at least 2021. The campaign utilizes various tools, including GoSerpent and Stowaway, for stealthy data exfiltration.
Operators initially establish a foothold, remain inactive for weeks to avoid detection, and then exfiltrate sensitive documents and credentials, targeting high-stakes information such as government files and biometric databases. Despite the TetrisPhantom group's possible involvement, exact attribution is uncertain. Kaspersky urges vigilance, recommending checks for malicious activities and extending log retention to catch delayed actions.