A previously undocumented China-aligned advanced persistent threat group, identified as LongNosedGoblin, has been conducting cyber espionage campaigns targeting government institutions in Southeast Asia and Japan. The group leverages Windows Group Policy, a trusted administrative tool in Active Directory environments, to deploy custom malware and move laterally within compromised networks. This approach allows the attackers to distribute malicious payloads at scale and blend their activity with legitimate administrative traffic, making detection more challenging. The campaign has been active since at least September 2023, with renewed activity observed in 2024.
LongNosedGoblin's toolset includes several custom C#/.NET applications such as NosyHistorian for browser history collection, NosyDoor for backdoor access and file exfiltration, NosyStealer for browser data theft, NosyDownloader for in-memory payload delivery, and NosyLogger for keystroke logging. The group uses cloud services like Microsoft OneDrive and Google Drive as command and control infrastructure, further complicating detection by hiding malicious communications within normal enterprise traffic. The initial access vector remains unknown, but the focus on government targets and the use of sophisticated techniques indicate a long-term surveillance objective aligned with Chinese state interests.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On December 18, 2025, ESET publicly revealed the previously undocumented group LongNosedGoblin, describing its abuse of Windows Group Policy, cloud-based command and control, and malware suite including NosyHistorian, NosyDoor, NosyStealer, NosyDownloader, and NosyLogger. ESET also said NosyDoor may be shared or commercially available among multiple China-aligned actors.
ESET found evidence that the group remained active through 2024 and into 2025, with updated tools and renewed operations. This indicated sustained espionage activity rather than a short-lived campaign.
By December 2024, an updated version of NosyDownloader had been used against a Japanese government target. This showed continued refinement of the malware and expansion of operations against high-value government victims.
During 2024, LongNosedGoblin's NosyDownloader malware was observed broadly across Southeast Asian targets. The tool was used to deliver additional payloads as part of the group's espionage operations.
Researchers discovered the campaign in early 2024 while observing simultaneous compromises inside a Southeast Asian government network. The activity revealed the group's use of Windows Group Policy abuse for malware deployment and lateral movement.
ESET assessed that the China-aligned espionage group LongNosedGoblin has been active since at least September 2023, targeting government institutions in Southeast Asia and Japan. The group focused on long-term surveillance and data theft using custom C#/.NET malware.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcedarkreading.com
Open sourcehelpnetsecurity.com
Open sourcethehackernews.com
Open sourcetherecord.media
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.