logo

China-Aligned APT Hackers Exploit Windows Group Policy to Deploy Malware

ID: 42d6589f-b3c3-556e-a244-67c8b0ac1fcd

STIX ID: report--42d6589f-b3c3-556e-a244-67c8b0ac1fcd

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A China-aligned APT named LongNosedGoblin has conducted targeted cyberespionage against governmental entities in Southeast Asia and Japan since at least September 2023, using custom C#/.NET malware (NosyDoor, NosyHistorian) and abusing Windows Group Policy/Active Directory for stealthy lateral movement and broad payload distribution. The group employs a multi-stage infection chain with DES-encrypted payloads, AppDomainManager DLL injection to bypass AMSI, scheduled-task persistence via a renamed legitimate binary, and OneDrive-based C2 to maintain long-term access and harvest intelligence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.