logo

New China-linked hacker group spies on governments in Southeast Asia, Japan

ID: a62a7d83-c109-5fb8-810a-f9fe0a4ff8b6

STIX ID: report--a62a7d83-c109-5fb8-810a-f9fe0a4ff8b6

Feed Name: The Record from Recorded Future News

Threat Score
85/100

Date Published: 2025-12-18

Date Updated: 2026-05-01

...
...

ESET uncovered a China-aligned APT called LongNosedGoblin targeting government institutions in Southeast Asia and Japan since at least September 2023; the group abuses legitimate Windows Group Policy to deploy malware families—NosyHistorian (browser-history collection), NosyDoor (backdoor), NosyStealer, NosyDownloader and NosyLogger—for targeted espionage and lateral movement, and some NosyDoor variants appear tailored to carefully selected machines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.