Malware
STOWAWAY
According to Mandiant, STOWAWAY is a publicly available backdoor and proxy. The project supports several types of communication like SSH, socks5. Backdoor component supports upload and download of files, remote shell and basic information gathering.
Indicators of Compromise 23
MD5 19f8befcb035f52bf70094e6b4f5779a MD5 64e9d1950e42bc98486dfd9919463d1c MD5 64e9d195e42bc98486dfdd9919463d1c MD5 7f223ee0716ce2ad56f55d3744419449 MD5 846ef7c1c7323849b2a778c5e4cda162 MD5 93a1569d5d5ab2c4761fedf84f83709e MD5 cb6c4c70a3b171fa3404b8e1a3382116 MD5 cbbb6d483737ea3566726e51752dff40 MD5 d08a059e8b815e3b891505bc8777fc28 MD5 d6e86bf8a90e9b632add5fa495f97fbc MD5 dc506ff7bb72735444fb3703a6bee6d8 MD5 ebffd5a76aaa690bcdb922f82e0bacc5 IP 101[.]36[.]104[.]87 IP 103[.]138[.]13[.]30 IP 144[.]48[.]6[.]46 IP 152[.]32[.]160[.]239 IP 152[.]32[.]222[.]113 IP 43[.]106[.]30[.]226 IP 47[.]80[.]22[.]58 IP 8[.]220[.]193[.]189 IP 8[.]220[.]194[.]108 IP 8[.]220[.]209[.]155 IP 8[.]220[.]214[.]132
MITRE ATT&CK TTPs 40
T1001.001 T1003.001 T1003.002 T1021.001 T1021.002 T1021.003 T1027 T1048.002 T1053.005 T1055 T1059.001 T1070.004 T1071.001 T1071.003 T1074.001 T1078.001 T1082 T1083 T1087.001 T1090.001 T1090.003 T1098 T1098.001 T1105 T1110 T1114 T1129 T1133 T1140 T1482 T1543.003 T1558.003 T1566 T1569.002 T1571 T1572 T1573 T1573.001 T1574 T1614
Junk Data
Command And Control
LSASS Memory
Credential Access
Security Account Manager
Credential Access
Remote Desktop Protocol
Lateral Movement
SMB/Windows Admin Shares
Lateral Movement
Distributed Component Object Model
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Exfiltration
Scheduled Task
Execution
Process Injection
Defense Evasion
PowerShell
Execution
File Deletion
Defense Evasion
Web Protocols
Command And Control
Mail Protocols
Command And Control
Local Data Staging
Collection
Default Accounts
Defense Evasion
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Local Account
Discovery
Internal Proxy
Command And Control
Multi-hop Proxy
Command And Control
Account Manipulation
Persistence
Additional Cloud Credentials
Persistence
Ingress Tool Transfer
Command And Control
Brute Force
Credential Access
Email Collection
Collection
Shared Modules
Execution
External Remote Services
Persistence
Deobfuscate/Decode Files or Information
Defense Evasion
Domain Trust Discovery
Discovery
Windows Service
Persistence
Kerberoasting
Credential Access
Phishing
Initial Access
Service Execution
Execution
Non-Standard Port
Command And Control
Protocol Tunneling
Command And Control
Encrypted Channel
Command And Control
Symmetric Cryptography
Command And Control
Hijack Execution Flow
Persistence
System Location Discovery
Discovery
Source Articles
GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
The GoSerpent campaign is a sophisticated and evolving threat targeting government and diplomatic entities in Southeast Asia since at least 2021, with ongoing activity observed through 2026. The primary malware, GoSerpent, is a Go-based backdoor that enables remote access, SOCKS5 proxying, and deployment of additional tools for data collection and credential dumping. In 2026, attackers expanded their toolkit with Stowaway, a new Go-based RAT, and TmcLoader/TmcPayload, a stealthy two-stage payload used for exfiltrating data collected by earlier stages. The attack chain demonstrates high operational integration, using credential dumping tools like Mimikatz and QuarksDumpLocalHash to enable lateral movement and exfiltration of archived sensitive files via network shares.
securelist ·1mo ago
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
A previously undocumented malware named GoSerpent has been used in cyber espionage campaigns targeting government and diplomatic entities in Southeast Asia since late 2025. The malware enables long-term access, credential dumping, and data exfiltration through a suite of tools including Mimikatz, QuarksDumpLocalHash, and a custom file collection tool called ThumbcacheService. In May 2026, attackers returned to compromised environments to deploy evolved tools such as Stowaway and TmcLoader/TmcPayload for further data exfiltration. The activity shows operational overlaps with the TetrisPhantom threat actor, though definitive attribution remains unconfirmed.
hacker-news ·1mo ago