LongNosedGoblin Unleashes Cyber Espionage Chaos: Southeast Asia and Japan Under Attack!

LongNosedGoblin, a China-aligned threat cluster, is on the cyber espionage prowl in Southeast Asia and Japan. Using Group Policy, malware like NosyDoor turns Microsoft OneDrive into a sneaky command center. ESET reports new variants are popping up like unwanted ads, possibly shared among multiple cyber baddies.

Pro Dashboard

Hot Take:

Just when you thought goblins were confined to fantasy novels, here comes LongNosedGoblin, a cyber threat actor that’s got Southeast Asian and Japanese governments wishing they had a wizard on speed dial. With a bag of tricks that would make any magician jealous, these cyber goblins are using Group Policy magic to exfiltrate data faster than you can say ‘NosyHistorian’. Someone call Gandalf; it’s goblin-hunting season!

Key Points:

– LongNosedGoblin is a newly identified China-aligned cyber threat.
– Targets include governmental entities in Southeast Asia and Japan.
– The group uses cloud services like OneDrive and Google Drive for command and control.
– A suite of custom tools, including NosyHistorian and NosyDoor, is employed for data exfiltration.
– Malware might be shared among multiple threat groups, suggesting a potential cyber crime franchise model.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?