securityonline.info 7/24/2026, 4:31:36 PM · external

GoSerpent backdoor fuels SE Asia gov cyber spying since 2021

GoSerpent backdoor fuels SE Asia gov cyber spying since 2021
CyberSIXT Evidence Panel
Primary Source securelist.com
Threat Actor

KASPERSKY'S GReAT team reported on July 16, 2026, about the GoSerpent backdoor, a long-running cyber espionage campaign targeting government and diplomatic networks in Southeast Asia since at least 2021. The campaign utilizes various tools, including GoSerpent and Stowaway, for stealthy data exfiltration.

Operators initially establish a foothold, remain inactive for weeks to avoid detection, and then exfiltrate sensitive documents and credentials, targeting high-stakes information such as government files and biometric databases. Despite the TetrisPhantom group's possible involvement, exact attribution is uncertain. Kaspersky urges vigilance, recommending checks for malicious activities and extending log retention to catch delayed actions.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline