Image Credentials: Image Title: Stealth Espionage: New China-Aligned Group “LongNosedGoblin” Abuses Windows Group Policy Source: (sora.openai) Date: December 2025. Attribution: This image was created using AI-generated imagery (sora.openai) and does not depict a real-world scene.
By Open Chronicle Staff with Agencies
ESET Research has uncovered a previously undocumented advanced persistent threat (APT) group, dubbed LongNosedGoblin, that has been targeting government institutions in Southeast Asia and Japan since at least September 2023. The group distinguishes itself through the clever abuse of Windows Group Policy to move laterally and maintain persistence within sensitive networks.
Unlike groups that rely on repeated software exploits, LongNosedGoblin leverages Windows Group Policy Objects (GPOs). Once the attackers gain initial access to a domain, they use GPOs to deploy malware across the entire network. This technique allows them to blend in with legitimate administrative traffic, making their movements nearly invisible to traditional security monitoring.
The group utilizes a specialized suite of C# and .NET tools, collectively referred to by researchers as the “Nosy” family. This modular toolkit is designed for deep surveillance and data theft:
- NosyHistorian: Harvests browsing history from Chrome, Edge, and Firefox to help operators identify high-value targets.
- NosyDoor: A reconnaissance tool that executes shell commands and manages file exfiltration.
- NosyStealer: Specifically targets stored browser credentials.
- NosyDownloader: An obfuscated loader that executes additional payloads directly in memory to avoid leaving “footprints” on the disk.
- NosyLogger: A keylogger based on the open-source DuckSharp project, used for stealing login credentials.
The group’s ambitions extend beyond simple document theft. ESET researchers observed the deployment of a reverse SOCKS5 proxy for remote network access and an “argument runner” designed to launch surveillance utilities. In one recorded instance, the group used FFmpeg to capture live audio and video from a compromised system, indicating a high-interest intelligence target.
To further evade detection, LongNosedGoblin hosts its command and control (C2) infrastructure on popular cloud services like Microsoft OneDrive, Google Drive, and Yandex Disk. By routing malicious traffic through these trusted platforms, the group ensures its communication is frequently overlooked by enterprise firewalls.
While primarily active in Southeast Asia and Japan, a variant of the NosyDoor malware was recently identified targeting an organization in the European Union. ESET researcher Anton Cherepanov suggests that the appearance of this malware across different regions and with varying techniques indicates that these tools may be shared among multiple China-aligned threat actors.
LongNosedGoblin represents a growing trend of “living off the land” (LotL) tactics, where attackers use a victim’s own administrative tools against them. Their reliance on GPO abuse and cloud-based C2 infrastructure demonstrates a highly disciplined approach to long-term espionage within the world’s most sensitive government environments.