China-aligned APT group targeting Asian governments via Group Policy and cloud-based C2 for cyberespionage.
Analyst brief
LongNosedGoblin is a China-aligned APT group targeting governmental entities for cyberespionage. The group focuses on victims in Southeast Asia and Japan, leveraging Group Policy for malware deployment. Their key TTPs include using cloud services like Microsoft OneDrive and Google Drive as C2 servers, deploying a modular malware ecosystem with backdoors and browser stealers, and executing multi-stage PowerShell-based payloads in memory. Defenders should monitor for unauthorized Group Policy modifications, anomalous traffic to legitimate cloud services, and suspicious in-memory PowerShell execution.
LongNosedGoblin
unknown
LongNosedGoblin is a China-aligned APT group targeting governmental entities in Southeast Asia and Japan for cyberespionage. The group employs Group Policy for malware deployment and utilizes cloud services like Microsoft OneDrive and Google Drive as C&C servers. Their operations feature a modular malware ecosystem, including backdoors, browser data stealers, and PowerShell-based downloaders that execute multi-stage payloads in memory. LongNosedGoblin's tactics emphasize reconnaissance-driven targeting and the abuse of trusted enterprise mechanisms, allowing for stealthy persistence within compromised networks.