Kaspersky uncovers a patient cyber-espionage campaign using new GoSerpent malware to harvest diplomatic secrets

https://www.itvoice.in/wp-content/uploads/2026/07/1bfa7690-a000-4972-b665-6ca4eb37e7f8.png

The new GoSerpent RAT targeted government and diplomatic entities in Southeast Asia. The campaign underscores the threat actor’s emphasis on maintaining long-term access and conducting intelligence collection.

In July 2026, researchers from the Kaspersky Global Research and Analysis Team (GReAT) team identified a new campaign, dubbed GoSerpent, representing a sophisticated and adaptive threat focused on the collection and exfiltration of sensitive data. According to the researchers, the operation relies on a set of customized tools, including the GoSerpent backdoor, Stowaway, and TmcLoader, reflecting a high level of technical capability and operational planning.

A central component of the campaign is the GoSerpent backdoor, a sophisticated Go-based Remote Access Trojan (RAT) that has reportedly been active since at least 2021, with the latest known variant deployed in 2026. The malware incorporates strong persistence mechanisms and uses filenames that imitate legitimate system processes to reduce the likelihood of detection.

“What stands out about...

Copyright of this story solely belongs to itvoice.in. To see the full text click HERE

Read more