Government agencies and diplomatic organizations in Southeast Asia (SEA) are facing a more advanced cyber threat as attackers continue to improve a malware campaign designed to steal sensitive information, according to cybersecurity company Kaspersky.

Researchers at Kaspersky said the malware, known as GoSerpent, has been active since at least 2021 but has evolved significantly in recent months. The latest version, discovered after an investigation in February 2026, is better at hiding from security software and gathering confidential files before quietly sending them to attackers.

The campaign primarily targets government and diplomatic organizations across SEA, raising concerns for public sector institutions and organizations that handle sensitive information in the region, including the Philippines.

“The campaign represents a sophisticated and evolving threat to government and diplomatic entities in Southeast Asia,” Noushin Shabab, lead security researcher, Global Research & Analysis Team, ANZ, wrote in the blog post on Kaspersky’s Securelist.

Kaspersky found that the attackers first infect a computer with GoSerpent, giving them remote access to the device. They then install additional tools that search for confidential documents, collect login credentials, and save the stolen data for later transfer. Months later, the attackers return with new tools to quietly move the collected information out of the victim’s network.

Researchers said the latest campaign began in late 2025 and continued into 2026. During monitoring, Kaspersky observed the attackers introducing a new remote access tool called Stowaway, along with another program designed to secretly transfer files gathered during earlier stages of the attack.

Unlike common cybercriminals that seek immediate financial returns through ransomware or fraud, this campaign appears to prioritize surveillance and intelligence collection over an extended period.

Kaspersky also noted that the attackers use legitimate cloud hosting services, including Alibaba Cloud and UCLOUD HK, to operate their infrastructure. Using trusted online services can make malicious activity harder to detect because the traffic blends in with normal internet use.

Although researchers found similarities between GoSerpent and a known threat group called TetrisPhantom, Kaspersky said there is not yet enough evidence to definitively attribute the attacks to that actor.

For organizations, the findings highlight the importance of regularly updating security systems, monitoring unusual network activity, and protecting employee credentials. Since the malware is designed to remain hidden while collecting information over several months, early detection is critical to limiting potential damage.

The report also serves as a reminder that cyber espionage remains an active risk in the SEA region as governments and organizations continue their digital transformation. Even businesses working with government agencies or handling sensitive information may become indirect targets if attackers view them as a pathway into larger networks.

Discover more from Back End News

Subscribe now to keep reading and get access to the full archive.

Continue reading