Kaspersky Researchers Identify New GoSerpent Malware Campaign Targeting Southeast Asian Diplomats
AI-generated from multiple sources. Verify before acting on this reporting.
MOSCOW — Russian cybersecurity firm Kaspersky announced on Wednesday the discovery of a sophisticated espionage campaign utilizing new malware variants to target government officials and diplomatic entities across Southeast Asia. The operation, identified as part of the broader TetrisPhantom threat actor group, has been active since late 2025 with significant tool evolution observed in May 2026.
The malicious software, named GoSerpent, is designed for long-term intelligence gathering within high-value networks. Researchers state that the campaign specifically focuses on ministries of foreign affairs and diplomatic missions throughout the Asia-Pacific region. The attack vector has shifted over time; while initial intrusions began in late 2025 using established methods, a distinct wave of activity emerged in May 2026 featuring evolved tools capable of bypassing modern security defenses.
The TetrisPhantom group is known for conducting state-sponsored cyberespionage operations. In this specific campaign, the objective remains strictly intelligence gathering rather than financial theft or infrastructure disruption. The malware establishes persistent access to compromised systems, allowing operators to exfiltrate sensitive communications and strategic documents from targeted diplomatic channels.
Kaspersky researchers detailed that the GoSerpent payload includes advanced evasion techniques designed to avoid detection by standard endpoint protection software. Since May 2026, the threat actors have deployed updated modules that enhance their ability to maintain stealth within compromised environments. The geographic scope of the attacks extends across multiple nations in Southeast Asia, with confirmed compromises affecting official government networks and diplomatic residences.
The timing of the campaign's escalation coincides with heightened geopolitical tensions in the region, though no direct link between specific political events and the cyber operations has been established by the researchers. The targeting pattern suggests a coordinated effort to map out regional security postures and gather intelligence on foreign policy strategies among Southeast Asian nations.
Security experts note that the evolution of GoSerpent indicates a maturing threat capability within the TetrisPhantom group. The shift from initial reconnaissance in late 2025 to active data exfiltration using new tools in mid-2026 marks a critical phase in the campaign's lifecycle. Organizations in the affected region are advised to audit their networks for signs of compromise, particularly those with diplomatic or high-level government functions.
As investigations continue, questions remain regarding the full extent of the data already exfiltrated and whether other sectors beyond diplomacy have been targeted. The cybersecurity community is monitoring for further variations of GoSerpent as threat actors refine their methods to maintain access against improving defensive measures.