Beneath the Radar: A Reawakened Espionage Toolkit Targets Southeast Asian Governments- 256
July 18, 2026
For over a year, an intrusion set moving through government and diplomatic networks across Southeast Asia left barely a trace — until Kaspersky, tracing a data-exfiltration tool back to its source, uncovered GoSerpent, a Go-based backdoor whose lineage stretches back to at least 2021 and whose current campaign reflects the patient, low-noise tradecraft characteristic of state-aligned intelligence collection.
What distinguishes this operation is less the initial compromise than its second act. Having established footholds in target networks and quietly harvested files for months, the operators returned in May 2026 with an upgraded toolset — a new proxy implant dubbed Stowaway and a purpose-built exfiltration tool, ThumbcacheService, designed to move previously staged data out through network shares rather than direct outbound connections, a technique that minimizes the kind of anomalous traffic that typically triggers detection. The addition of Mimikatz for credential harvesting and QuarksDumpLocalHash for offline password-hash extraction rounds out a toolkit oriented entirely toward sustained access rather than smash-and-grab theft.
Kaspersky's attribution remains deliberately cautious, but the operational fingerprint — targeting, tradecraft, and infrastructure overlaps — points toward TetrisPhantom, a threat actor the firm first documented in 2023 for a campaign notable for its use of hardware-encrypted USB drives to physically ferry stolen data between air-gapped government systems. That such tooling continues to evolve against the same regional target set suggests a standing intelligence requirement rather than an opportunistic campaign.
The disclosure arrived alongside a second, separately attributed operation: Bangladesh's military and defense establishment came under a spear-phishing campaign traced to DoNot Team, using a weaponized RTF document, geofenced payload delivery restricted to victims physically inside the target region, and a DLL implant disguised as routine OneDrive telemetry. The near-simultaneous disclosure of two distinct espionage operations against South and Southeast Asian government targets — one refining a multi-year toolkit, the other deploying region-locked delivery infrastructure — underscores a persistent and diversified intelligence-collection pressure across the region, absorbed by defenders largely without public acknowledgment until researchers surface it independently.