LongNosedGoblin Caught Snooping on Asian Governments
ID: 51e5f14a-cf9e-57fc-89a5-5058645163de
STIX ID: report--51e5f14a-cf9e-57fc-89a5-5058645163de
Feed Name: Dark Reading
Executive summary: ESET researchers identified a China-linked APT they call LongNosedGoblin that has targeted government organizations in Japan and Southeast Asia since at least 2023. The group uses custom C#/.NET tooling and notably abuses Active Directory Group Policy as a malware dropper and lateral-movement mechanism; its toolkit includes reconnaissance (NosyHistorian), backdoors (NosyDoor), data exfiltration and infostealers, downloaders, keyloggers, proxies, and capabilities to capture audio/video, with OneDrive used for C2.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
