hacker-news · Crawled Jul 17, 2026
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
2 Actors 2 Malware
Read original article ↗
AI Summary
A previously undocumented malware named GoSerpent has been used in cyber espionage campaigns targeting government and diplomatic entities in Southeast Asia since late 2025. The malware enables long-term access, credential dumping, and data exfiltration through a suite of tools including Mimikatz, QuarksDumpLocalHash, and a custom file collection tool called ThumbcacheService. In May 2026, attackers returned to compromised environments to deploy evolved tools such as Stowaway and TmcLoader/TmcPayload for further data exfiltration. The activity shows operational overlaps with the TetrisPhantom threat actor, though definitive attribution remains unconfirmed.
AI-extracted · verify before operational use
Extracted Entities 4 found
MITRE ATT&CK TTPs 45 techniques
T1021.003 Distributed Component Object Model · Lateral Movement T1059.001 PowerShell · Execution T1071.001 Web Protocols · Command And Control T1082 System Information Discovery · Discovery T1083 File and Directory Discovery · Discovery T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1110 Brute Force · Credential Access T1114 Email Collection · Collection T1129 Shared Modules · Execution T1133 External Remote Services · Persistence T1140 Deobfuscate/Decode Files or Information · Defense Evasion T1566 Phishing · Initial Access T1573 Encrypted Channel · Command And Control T1574 Hijack Execution Flow · Persistence T1003 OS Credential Dumping · Credential Access T1018 Remote System Discovery · Discovery T1021 Remote Services · Lateral Movement T1021.001 Remote Desktop Protocol · Lateral Movement T1021.002 SMB/Windows Admin Shares · Lateral Movement T1033 System Owner/User Discovery · Discovery T1046 Network Service Discovery · Discovery T1048 Exfiltration Over Alternative Protocol · Exfiltration T1053 Scheduled Task/Job · Execution T1055.003 Thread Execution Hijacking · Defense Evasion T1057 Process Discovery · Discovery T1070.001 Clear Windows Event Logs · Defense Evasion T1074 Data Staged · Collection T1078 Valid Accounts · Defense Evasion T1086 T1086 T1087.002 Domain Account · Discovery T1110.003 Password Spraying · Credential Access T1112 Modify Registry · Defense Evasion T1212 Exploitation for Credential Access · Credential Access T1222 File and Directory Permissions Modification · Defense Evasion T1222.001 Windows File and Directory Permissions Modification · Defense Evasion T1482 Domain Trust Discovery · Discovery T1484.001 Group Policy Modification · Defense Evasion T1485 Data Destruction · Impact T1486 Data Encrypted for Impact · Impact T1489 Service Stop · Impact T1490 Inhibit System Recovery · Impact T1537 Transfer Data to Cloud Account · Exfiltration T1547.001 Registry Run Keys / Startup Folder · Persistence T1562.001 Disable or Modify Tools · Defense Evasion