Key Findings GoSerpent backdoor has targeted Southeast Asian government and diplomatic networks since at least 2021 Campaign demonstrates extreme patience, with operators waiting weeks between infection and data exfiltration to evade log retention systems Stolen credentials enable final data theft to appear as legitimate internal file-share access, bypassing standard network monitoring Toolchain includes GoSerpent RAT, ThumbcacheService collector, credential dumpers, Stowaway