LongNosedGoblin is a China-aligned advanced persistent threat group engaged in cyberespionage against government institutions in Southeast Asia and Japan since at least September 2023. The group is distinguished by its abuse of Windows Active Directory Group Policy to deploy malware at scale and move laterally within compromised domains, indicating access to domain controllers and domain administrator privileges in victim environments. Its operations are oriented toward long-term surveillance, intelligence collection, and sustained access rather than disruptive or financially motivated activity. The actor primarily uses a custom C#/.NET toolset. Reported malware associated with LongNosedGoblin includes NosyHistorian, NosyDoor, NosyStealer, NosyDownloader, and NosyLogger, along with supporting utilities such as a reverse SOCKS5 proxy and tooling used to launch audio or video capture components. NosyHistorian is used to inspect browser history and help identify higher-value targets inside a compromised organization. Only a subset of infected systems appears to receive the NosyDoor backdoor, reflecting selective follow-on targeting. NosyDoor supports remote command execution, file operations, metadata collection, and loading of additional .NET components, while NosyStealer is used to collect browser data, NosyDownloader delivers in-memory payloads, and NosyLogger provides keylogging capability. LongNosedGoblin relies on defense-evasion and living-off-the-land techniques, including AppDomainManager injection, AMSI bypass in parts of its toolchain, use of legitimate administrative mechanisms, and malware masquerading as benign policy-related artifacts. The group also uses trusted cloud services for command and control and exfiltration, including platforms such as OneDrive and Google Drive, helping its traffic blend with normal enterprise activity. Execution guardrails have been observed in some samples, suggesting victim-specific tasking. The group has been described as moderately sophisticated and appears focused on post-compromise expansion, persistence, surveillance, and data theft inside government networks. Its tradecraft and tooling show overlap with other China-nexus clusters, and NosyDoor in particular has been assessed as likely shared among multiple China-aligned actors. Similarities have been noted with ToddyCat and Erudite Mogwai, but LongNosedGoblin is treated as a distinct cluster, especially because of its characteristic use of Group Policy for malware deployment and lateral movement.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously disclosed China-nexus threat cluster that shares tooling and techniques with UAT-8302, indicating a close operational relationship.
Threat group associated by ESET with use of NosyDoor.
China-aligned espionage cluster targeting government entities in Southeast Asia and Japan; noted for using Windows Group Policy for malware deployment.
LongNosedGoblin is a China-aligned APT conducting cyber-espionage campaigns targeting government networks in Southeast Asia and Japan, leveraging Group Policy abuse for lateral movement and cloud services for command and control.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.