GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia. Continue reading GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia. Continue reading GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor

Kaspersky discloses a 2025 HoneyMyte (aka Mustang Panda or Bronze President) APT campaign, which uses a kernel-mode rootkit to deliver and protect a ToneShell backdoor. Continue reading The HoneyMyte APT evolves with a kernel-mode rootkit and a ToneShell backdoor

Spring Dragon – Updated Activity

In the beginning of 2017, Kaspersky Lab became aware of new activities by an APT actor we have been tracking for several years called Spring Dragon (also known as LotusBlossom). Information about the new attacks arrived from a research partner in Taiwan and we decided to review the actor’s tools, techniques and activities. Continue reading Spring Dragon – Updated Activity