ESET Identifies LongNosedGoblin APT Group Targeting Governments in Southeast Asia and Japan
ESET researchers have uncovered a new China-aligned Advanced Persistent Threat (APT) group named LongNosedGoblin, which has been actively conducting cyberespionage against governmental entities in Southeast Asia and Japan since at least September 2023. The group utilizes a custom toolset primarily built with C# and .NET applications. A distinctive feature of their operations is the abuse of Windows Group Policy to deploy malware and facilitate lateral movement across compromised networks. Key tools include NosyHistorian, which collects browser history to identify high-value targets for further infection, and NosyDoor, a backdoor that leverages cloud services like Microsoft OneDrive for command and control communications. The arsenal also includes NosyStealer for data exfiltration, NosyLogger for keylogging, and various downloaders. Notably, several of these tools employ techniques to bypass the Antimalware Scan Interface (AMSI), allowing them to evade detection by security products. This discovery highlights the evolving tactics of state-aligned threat actors who increasingly rely on living-off-the-land techniques and legitimate cloud infrastructure to maintain persistent access to sensitive government networks while avoiding traditional security defenses.
Wire timeline
ESET Identifies LongNosedGoblin APT Group Targeting Governments in Southeast Asia and Japan
ESET researchers have uncovered a new China-aligned Advanced Persistent Threat (APT) group named LongNosedGoblin, which has been actively conducting cyberespionage against governmental entities in Southeast Asia and Japan since at least September 2023. The group utilizes a custom toolset primarily built with C# and .NET applications. A distinctive feature of their operations is the abuse of Windows Group Policy to deploy malware and facilitate lateral movement across compromised networks. Key tools include NosyHistorian, which collects browser history to identify high-value targets for further infection, and NosyDoor, a backdoor that leverages cloud services like Microsoft OneDrive for command and control communications. The arsenal also includes NosyStealer for data exfiltration, NosyLogger for keylogging, and various downloaders. Notably, several of these tools employ techniques to bypass the Antimalware Scan Interface (AMSI), allowing them to evade detection by security products. This discovery highlights the evolving tactics of state-aligned threat actors who increasingly rely on living-off-the-land techniques and legitimate cloud infrastructure to maintain persistent access to sensitive government networks while avoiding traditional security defenses.
WeLiveSecurity