logo

LongNosedGoblin Caught Snooping on Asian Governments

ID: 51e5f14a-cf9e-57fc-89a5-5058645163de

STIX ID: report--51e5f14a-cf9e-57fc-89a5-5058645163de

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-12-19

Date Updated: 2026-04-21

Author: Becky Bracken

...
...

Executive summary: ESET researchers identified a China-linked APT they call LongNosedGoblin that has targeted government organizations in Japan and Southeast Asia since at least 2023. The group uses custom C#/.NET tooling and notably abuses Active Directory Group Policy as a malware dropper and lateral-movement mechanism; its toolkit includes reconnaissance (NosyHistorian), backdoors (NosyDoor), data exfiltration and infostealers, downloaders, keyloggers, proxies, and capabilities to capture audio/video, with OneDrive used for C2.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.