BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

China-Aligned LongNosedGoblin Malware Targets Asia-Pacific Governments

China-aligned LongNosedGoblin cyber espionage targets Southeast Asia and Japan using Windows Group Policy and cloud services for malware deployment and data theft.

  • A China-aligned Hacking group called LongNosedGoblin has targeted governments in Southeast Asia and Japan since September 2023.
  • The group uses Windows Group Policy to deploy Malware and cloud storage services for command and control (C&C) communication.
  • The attackers employ various custom tools to steal browser data, log keystrokes, and exfiltrate files using services like Microsoft OneDrive, Google Drive, and Yandex Disk.
  • LongNosedGoblin’s malware shows some similarities with other clusters but remains distinct, with potential sharing of tools among China-aligned groups.

A China-aligned cyber threat cluster named LongNosedGoblin has conducted espionage-focused cyber attacks on government entities in Southeast Asia and Japan since at least September 2023. The group uses Windows Group Policy, a system for managing computer and user settings, to spread malware within targeted networks.

- Advertisement -

Security researchers Anton Cherepanov and Peter Strýček stated that LongNosedGoblin leverages cloud services such as Microsoft OneDrive and Google Drive as command and control (C&C) servers. The attack toolkit mainly includes C#/.NET applications designed for data theft and remote control.

Their malware lineup features:
– NosyHistorian, which collects browsing histories from Google Chrome, Microsoft Edge, and Mozilla Firefox.
– NosyDoor, a backdoor that uses OneDrive for C&C and can exfiltrate or delete files, as well as execute shell commands.
– NosyStealer, which steals browser data from Chrome and Edge, encrypting it into TAR archives uploaded to Google Drive.
– NosyDownloader, used to run additional payloads like NosyLogger in memory.
– NosyLogger, a modified keylogger based on DuckSharp software, capturing keystrokes.

ESET first detected LongNosedGoblin activity in February 2024 on a Southeast Asian government system. The malware spread through Group Policy to multiple computers within the same organization. The exact method by which the attackers initially gained access remains unknown. Analysis revealed targeted deployment, as only some victims infected with NosyHistorian also received the NosyDoor backdoor, which includes “execution guardrails” to limit infections to specific machines.

Additional tools used by the group include a reverse SOCKS5 proxy, software to record audio and video, and a Cobalt Strike loader. Although the group’s tactics show weak similarities to those of ToddyCat and Erudite Mogwai clusters, firm links have not been established. The resemblance of NosyDoor to the LuckyStrike Agent malware and the phrase “Paid Version” found in LuckyStrike’s programming hint that some LongNosedGoblin tools could be commercially available or shared among China-aligned actors.

- Advertisement -

Researchers also identified a NosyDoor variant targeting an organization in the European Union, which replaced its C&C with Yandex Disk, suggesting LongNosedGoblin malware may be utilized by multiple related threat groups.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

North Korean hacking group WaterPlum stole $10.7M

North Korean Hacking group WaterPlum stole at least $10.7 million by posing as recruiters...

Coinbase CEO: SEC, CFTC rules more lenient than failed bill

Coinbase CEO Brian Armstrong says the failure of the CLARITY Act may reduce competition...

Visser: AI Agents Are Crypto’s Real Customers, Not Humans

Bitcoin has joined religion and Gold as the only things that survive human and...

Grayscale Zcash ETF Announces 3-for-1 Share Split

Grayscale's ZCash ETF (ZCSH) will execute a 3-for-1 forward share split on Sept. 28,...

REX Launches 2x Leveraged ETF on Bitcoin Treasury Strive

REX Shares and Tuttle Capital Management launched the ASSX ETF on Cboe, offering 2x...

Must Read

What Is Binance Earn?

As someone who is passionate about cryptocurrency, I am always on the lookout for new opportunities to grow my portfolio. That's why I was...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading