Malware

STOWAWAY

According to Mandiant, STOWAWAY is a publicly available backdoor and proxy. The project supports several types of communication like SSH, socks5. Backdoor component supports upload and download of files, remote shell and basic information gathering.

Indicators of Compromise 23

MITRE ATT&CK TTPs 40

T1001.001
Junk Data
Command And Control
T1003.001
LSASS Memory
Credential Access
T1003.002
Security Account Manager
Credential Access
T1021.001
Remote Desktop Protocol
Lateral Movement
T1021.002
SMB/Windows Admin Shares
Lateral Movement
T1021.003
Distributed Component Object Model
Lateral Movement
T1027
Obfuscated Files or Information
Defense Evasion
T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Exfiltration
T1053.005
Scheduled Task
Execution
T1055
Process Injection
Defense Evasion
T1059.001
PowerShell
Execution
T1070.004
File Deletion
Defense Evasion
T1071.001
Web Protocols
Command And Control
T1071.003
Mail Protocols
Command And Control
T1074.001
Local Data Staging
Collection
T1078.001
Default Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1083
File and Directory Discovery
Discovery
T1087.001
Local Account
Discovery
T1090.001
Internal Proxy
Command And Control
T1090.003
Multi-hop Proxy
Command And Control
T1098
Account Manipulation
Persistence
T1098.001
Additional Cloud Credentials
Persistence
T1105
Ingress Tool Transfer
Command And Control
T1110
Brute Force
Credential Access
T1114
Email Collection
Collection
T1129
Shared Modules
Execution
T1133
External Remote Services
Persistence
T1140
Deobfuscate/Decode Files or Information
Defense Evasion
T1482
Domain Trust Discovery
Discovery
T1543.003
Windows Service
Persistence
T1558.003
Kerberoasting
Credential Access
T1566
Phishing
Initial Access
T1569.002
Service Execution
Execution
T1571
Non-Standard Port
Command And Control
T1572
Protocol Tunneling
Command And Control
T1573
Encrypted Channel
Command And Control
T1573.001
Symmetric Cryptography
Command And Control
T1574
Hijack Execution Flow
Persistence
T1614
System Location Discovery
Discovery

Source Articles

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
The GoSerpent campaign is a sophisticated and evolving threat targeting government and diplomatic entities in Southeast Asia since at least 2021, with ongoing activity observed through 2026. The primary malware, GoSerpent, is a Go-based backdoor that enables remote access, SOCKS5 proxying, and deployment of additional tools for data collection and credential dumping. In 2026, attackers expanded their toolkit with Stowaway, a new Go-based RAT, and TmcLoader/TmcPayload, a stealthy two-stage payload used for exfiltrating data collected by earlier stages. The attack chain demonstrates high operational integration, using credential dumping tools like Mimikatz and QuarksDumpLocalHash to enable lateral movement and exfiltration of archived sensitive files via network shares.
securelist ·1mo ago
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
A previously undocumented malware named GoSerpent has been used in cyber espionage campaigns targeting government and diplomatic entities in Southeast Asia since late 2025. The malware enables long-term access, credential dumping, and data exfiltration through a suite of tools including Mimikatz, QuarksDumpLocalHash, and a custom file collection tool called ThumbcacheService. In May 2026, attackers returned to compromised environments to deploy evolved tools such as Stowaway and TmcLoader/TmcPayload for further data exfiltration. The activity shows operational overlaps with the TetrisPhantom threat actor, though definitive attribution remains unconfirmed.
hacker-news ·1mo ago