Executive Summary
The GoSerpent campaign is a sophisticated, multi-stage attack targeting government and diplomatic entities in Southeast Asia since at least 2021, with evolved variants deployed through 2026. The Go-based GoSerpent backdoor establishes persistent access and deploys ThumbcacheService for document collection, Mimikatz and QuarksDumpLocalHash for credential dumping, and later stages use Stowaway RAT and TmcLoader/TmcPayload to exfiltrate collected data via network shares using stolen credentials. The tight integration between collection, credential theft, and exfiltration components demonstrates advanced operational planning and long-term intelligence gathering objectives.
Why This Matters Now
The GoSerpent campaign exemplifies the increasing sophistication of APTs targeting sensitive government sectors, highlighting the urgent need for enhanced cybersecurity measures and vigilance against evolving threats.
Attack Path Analysis
The GoSerpent campaign began with the deployment of the GoSerpent backdoor, allowing attackers to gain initial access to target systems. Subsequently, they escalated privileges by deploying credential dumping tools like Mimikatz to extract sensitive credentials. With elevated access, the attackers moved laterally within the network, deploying additional tools such as ThumbcacheService for data collection. They established command and control channels using the GoSerpent backdoor's proxy capabilities to maintain persistent access. Sensitive data was exfiltrated through network shares using tools like TmcLoader/TmcPayload. The campaign's impact included unauthorized access to sensitive government and diplomatic information, leading to potential intelligence compromises.
Kill Chain Progression
Initial Compromise
Description
Attackers deployed the GoSerpent backdoor to gain initial access to target systems.
MITRE ATT&CK® Techniques
Command and Scripting Interpreter: PowerShell
Application Layer Protocol: Web Protocols
Proxy
OS Credential Dumping: LSASS Memory
Ingress Tool Transfer
Masquerading: Match Legitimate Name or Location
Indicator Removal: File Deletion
Hide Artifacts: Hidden File System
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure the security of all system components
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Direct targeting of government entities in Southeast Asia by GoSerpent APT with sophisticated data exfiltration, credential dumping, and persistent backdoor access capabilities.
International Affairs
Diplomatic entities specifically targeted for sensitive document theft using multi-stage malware with encrypted communications and long-term intelligence gathering operations.
Computer/Network Security
Critical infrastructure vulnerabilities exposed through advanced persistent threat techniques including zero-day exploits, lateral movement, and encrypted traffic manipulation for data exfiltration.
Information Technology/IT
Multi-cloud environments at risk from sophisticated segmentation bypass, east-west traffic exploitation, and Kubernetes security compromises enabling widespread organizational infiltration.
Sources
- GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltrationhttps://securelist.com/goserpent-backdoor-in-southeast-asia/120687/Verified
- Kaspersky reveals new HoneyMyte APT campaigns and toolsethttps://www.kaspersky.com/about/press-releases/kaspersky-reveals-new-honeymyte-apt-campaigns-and-toolsetVerified
- OceanLotus targets Vietnamese investors and infrastructure firm with SPECTRALVIPERhttps://www.isec.news/2026/06/12/oceanlotus-targets-vietnamese-investors-and-infrastructure-firm-with-spectralviper/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to the GoSerpent campaign as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been constrained by identity-aware policies, reducing unauthorized entry points.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could have been limited by restricting access to sensitive credentials.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the network would likely be constrained, reducing the spread of malicious tools.
Control: Multicloud Visibility & Control
Mitigation: The attacker's command and control channels may have been detected and disrupted, limiting persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts could have been restricted, reducing unauthorized data transfers.
The overall impact of the campaign would likely be reduced, limiting unauthorized access to sensitive information.
Impact at a Glance
Affected Business Functions
- Government Communications
- Diplomatic Correspondence
- Classified Document Management
Estimated downtime: 14 days
Estimated loss: $500,000
Confidential government documents, diplomatic communications, and sensitive credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement and limit the spread of malware within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to suspicious activities promptly.
- • Enforce East-West Traffic Security to monitor and control internal network communications, reducing the risk of lateral movement.
- • Apply Encrypted Traffic (HPE) to secure data in transit, protecting sensitive information from interception during exfiltration attempts.



