In July 2026, researchers from Kaspersky’s Global Research and Analysis Team (GReAT) uncovered a sophisticated cyber campaign dubbed GoSerpent, designed to collect and exfiltrate sensitive data. The operation employs a customized toolkit, including the GoSerpent backdoor, Stowaway, and TmcLoader, demonstrating advanced technical capabilities and careful operational planning, a press release said.
At the core of the campaign is the GoSerpent backdoor, a Go-based Remote Access Trojan (RAT) active since at least 2021, with its latest known variant observed in 2026. The malware establishes strong persistence and disguises itself using filenames that mimic legitimate system processes, helping it evade detection.
“What stands out about GoSerpent is the deliberate dwell time. Usually, attackers want to move quickly once they get a foothold, but this group drops the initial backdoor and waits. They let the dust settle for weeks before deploying their secondary exfiltration tools like TmcLoader. That kind of patience is a calculated move designed to outlast standard log retention policies and automated security sweeps, making it incredibly difficult for defenders to connect the initial infection to the eventual data theft,” — says Noushin Shabab, Lead Security Researcher in Kaspersky GReAT.
Kaspersky researchers suspect links between the GoSerpent campaign and the TetrisPhantom threat actor based on shared victim profiles, technical characteristics, and operational methods, although attribution remains under investigation.
To reduce risk, Kaspersky recommends that organizations monitor for GoSerpent indicators of compromise (IoCs), strengthen threat detection and response capabilities with solutions such as Kaspersky Next, secure email infrastructure with Kaspersky Security for Mail Server, monitor external exposure using Kaspersky Digital Footprint Intelligence, and enhance cyber resilience through Kaspersky Compromise Assessment, Managed Detection and Response, and Incident Response services. The full technical report is available on Securelist.
