A China -linked threat group called LongNosedGoblin has been linked to a series of cyberattacks targeting government organizations in Southeast Asia and Japan . The ultimate goal of these attacks is cyberespionage , according to Slovakian cybersecurity firm ESET . The group is estimated to have been active since at least September 2023.

“ LongNosedGoblin uses Group Policy to deploy malware across the compromised network and cloud services (e.g. Microsoft OneDrive and Google Drive) as command and control (C&C) servers Windows ,” security researchers Anton Cherepanov and Peter Strýček reported .
See also: Kimwolf Botnet has infected 1.8 million Android devices
Group Policy is a mechanism for managing settings and permissions on machines running Windows. According to Microsoft, Group Policy can be used to define configurations for groups of users and client computers, as well as to manage server computers.
LongNosedGoblin: What tools do hackers use?
The attacks are characterized by the use of a custom toolset consisting mainly of C#/.NET applications:
– NosyHistorian, for collecting browsing history from Google Chrome, Microsoft Edge and Mozilla Firefox
– NosyDoor, a backdoor that uses Microsoft OneDrive as a C&C and executes commands that allow it to extract files, delete files, and execute shell commands
– NosyStealer, for exporting browsing data from Google Chrome and Microsoft Edge to Google Drive in the form of an encrypted TAR file
– NosyDownloader, for downloading and executing a payload in memory, like NosyLogger
– NosyLogger, a modified version of DuckSharp used to record keystrokes
See also: New ForumTroll Phishing Attacks Target Russian Academics

ESET said it first detected activity linked to the group in February 2024. It was detected on a system government organization in Southeast Asia, eventually discovering that Group Policy was used to deliver the malware to multiple systems from the same organization.
The exact initial access methods used in the attacks are currently unknown. Further analysis has determined that while many victims were affected by NosyHistorian between January and March 2024, only a subset of these victims were infected with NosyDoor, indicating a more targeted approach.
In some cases, the dropper used to deploy the backdoor, via AppDomainManager injection, contained “execution guardrails” designed to restrict operation to specific victim machines.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The LongNosedGoblin group also uses other tools such as a SOCKS5 proxy, a utility used to run a video recorder to record audio and video, and a Cobalt Strike loader.
See also: Kimsuky distributes Android malware DocSwap via QR codes

The cybersecurity firm noted that the group's technique has some slight similarities to groups monitored as ToddyCat and Erudite Mogwai, but emphasized the lack of definitive evidence linking them.
However, the similarities between NosyDoor and LuckyStrike Agent and the presence of the phrase “Paid Version” in LuckyStrike Agent’s PDB path have raised the possibility that the malware may be sold to other threat groups.
“We later identified another instance of a NosyDoor variant targeting an organization in an EU country, again using different TTPs and using the Yandex Disk cloud service as a C&C server,” the researchers noted. “The use of this NosyDoor variant suggests that the malware may be shared among multiple China-linked threat groups.”
