The Backdoor That Waited
Eight Months Before It Struck
Kaspersky's threat hunters just pulled back the curtain on an operation that's been running quietly inside Southeast Asian government and diplomatic networks since late 2025 — and the thing that should worry you isn't the malware itself. It's the patience. A backdoor called GoSerpent slipped into target systems, went dark, and waited. No smash-and-grab, no ransom note. Just months of silent collection before a single byte moved anywhere.
Kaspersky first spotted the activity in February, but the operators didn't show their full hand until May, when they came back into networks they'd already compromised and dropped a second wave of tools — a proxy-and-tunnel kit called Stowaway, a loader called TmcLoader, and a payload built purely to move out data that had already been quietly staged for weeks. In between, GoSerpent had been busy: setting up SOCKS5 proxies to mask its traffic, deploying Mimikatz to pull credentials straight out of memory, and running a custom collection tool nicknamed ThumbcacheService to inventory sensitive files before anyone knew to look.
"The chain from ThumbcacheService to TmcLoader/TmcPayload demonstrates sophisticated operational planning."
— Kaspersky (Noushin Shabab), July 2026That phrase — "operational planning" — is doing a lot of work. This isn't a script kiddie's smash-and-grab. It's staged the way a case officer stages an exfil: recon first, quiet collection second, extraction only once the target's guard is down and the tradecraft's been tested. Kaspersky also flagged overlap with TetrisPhantom, an operator they first caught in 2023 running a scheme so patient it compromised the secure, hardware-encrypted USB drives diplomats use to move data between air-gapped systems — turning the very tool meant to keep a network safe into the courier.
For defenders, the lesson isn't "patch faster." It's that dwell time is the whole game. An intrusion that sits quiet for months isn't failing — it's working exactly as designed. By the time the exfiltration tools show up, the real damage was already done in the collection phase nobody detected.
Key Takeaways
- GoSerpent has targeted Southeast Asian government and diplomatic networks since late 2025, built for long-term access rather than immediate theft.
- Operators returned to already-compromised networks in May 2026 to deploy a second toolkit — proof of staged, multi-phase tradecraft, not a single smash-and-grab.
- The intrusion chain used SOCKS5 proxies, credential dumpers like Mimikatz, and a custom file-collection tool to quietly stage data for weeks before exfiltration.
- Kaspersky ties the campaign to TetrisPhantom, a threat actor previously caught exploiting secure USB drives to move stolen data off air-gapped diplomatic systems.
The Blake MacKay Connection
Blake's tradecraft runs on exactly this kind of patience — get in, go quiet, let the target's guard down before you ever touch the real objective. GoSerpent just proved that doctrine works as well against a government server as it does against a person. Start the series free with Intercept and watch that patience play out on the page.
Read the Full Article at The Hacker News → ← Back to Intel Briefing