logo

LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan

ID: 0cff7bd4-cd34-5abd-a2a3-252426f154b9

STIX ID: report--0cff7bd4-cd34-5abd-a2a3-252426f154b9

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
88/100

Date Published: 2025-12-18

Date Updated: 2026-05-01

...
...

ESET researchers discovered and analyzed a previously undocumented China‑aligned APT they named LongNosedGoblin, which targeted governmental entities in Southeast Asia and Japan for cyberespionage. The group uses a diverse custom .NET/Go toolset (NosyHistorian, NosyDoor, NosyStealer, NosyDownloader, NosyLogger, ReverseSocks5 and others), performs lateral movement via Active Directory Group Policy, leverages cloud services (OneDrive, Google Drive/Docs) for C2 and exfiltration, and employs advanced evasion techniques including AppDomainManager injection and AMSI bypass; the report includes detailed technical analysis, IoCs, and MITRE ATT&CK mappings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.