The record
Written from the 1 report below. Nothing here is unsourced.
- Cybersecurity researchers at Kaspersky have discovered a previously undocumented malware called GoSerpent, used in espionage attacks against government and diplomatic entities in Southeast Asia since late 2025.
- The malware connects to attacker-controlled servers, harvests sensitive files, steals system credentials, and can deploy additional tools for data collection and exfiltration.
- In May 2026, the attackers returned with evolved tools to exfiltrate months of collected data.
- The campaign shows overlaps with a known threat actor called TetrisPhantom, and a separate report detailed DoNot Team's espionage operation targeting Bangladesh's military using spear-phishing emails.
What to watch next
- Whether further GoSerpent variants or attacks emerge, given activity dating back to 2021
- Progress on attributing the campaign, as links to TetrisPhantom remain uncertain
- Whether DoNot Team's operation against Bangladesh's military expands to additional targets
Coverage1
All filed from India
Named Singapore · Thailand · Vietnam · Malaysia · Indonesia · Philippines · Cambodia · Laos · Myanmar (Burma) · Bangladesh · Baskar M · Cyderes Howler Cell · DoNot Team · GoSerpent · Kaspersky · McMx RAT · Mimikatz · Noushin Shabab · QuarksDumpLocalHash · Rahul Ramesh · Reegun Jayapaul · Stowaway
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
