• About
  • Subscribe
  • Contact
Monday, December 22, 2025
    Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
  • Events
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
  • Events
No Result
View All Result
FutureCISO
No Result
View All Result
Home Technology Data Protection

ESET: LongNosedGoblin deploys cyberespionage tools in Southeast Asia and Japan

FutureCISO Editors by FutureCISO Editors
December 22, 2025
APAC accounts for a third of cyberattacks in 2024

Photo by Lucas Andrade: https://www.pexels.com/photo/a-person-holding-a-tablet-device-with-skull-image-near-blackboard-14066351/

Share on FacebookShare on Twitter

ESET Research calls out the emergence of a new Advanced Persistent Threat (APT) group named LongNosedGoblin, believed to be aligned with Chinese interests, that has been actively targeting governmental bodies in Southeast Asia and Japan.

ESET researchers initially identified previously undocumented malware within the system of a Southeast Asian governmental entity in 2024. Since then, further investigations have linked these malicious activities to LongNosedGoblin which has reportedly been operational since at least September 2023.

The group's tactics involve the use of Group Policy—a feature in Windows that manages settings across networks—to deploy malware and facilitate lateral movement within compromised systems.

This discovery highlights the growing sophistication of cyberespionage efforts in the region, as this group employs various techniques to infiltrate and exploit networks.

One of the key tools used by LongNosedGoblin is NosyHistorian, a C#/.NET application designed to collect browser history from widely used web browsers such as Google Chrome and Mozilla Firefox.

This data is utilised to inform the group on where to deploy additional malware, including the NosyDoor backdoor, which collects vital metadata from infected machines and communicates with cloud-based Command & Control (C&C) servers, such as Microsoft OneDrive and Google Drive.

ESET's findings indicate that LongNosedGoblin employs a range of sophisticated tools, including NosyStealer, which siphons browser data, and NosyDownloader, which executes obfuscated commands to download malicious payloads. Notably, the group also utilises a keylogger named NosyLogger, likely a modified version of the open-source keylogger DuckSharp, to capture keystrokes discreetly.

Researchers also observed a variant of NosyDoor targeting an organisation in an EU country, deploying different techniques, which suggests that this malware may be shared among various China-aligned threat actors. This underscores a concerning pattern of cross-collaboration among cybercriminals.

Related:  F5 introduces NGINX One to streamline application security and delivery

ESET researcher Anton Cherepanov said te identification of LongNosedGoblin and its arsenal signifies an evolving threat landscape that demands heightened awareness from governmental institutions and cybersecurity professionals alike.

Tags: APT threatsESET
FutureCISO Editors

FutureCISO Editors

No Result
View All Result

Recent Posts

  • ESET: LongNosedGoblin deploys cyberespionage tools in Southeast Asia and Japan
  • Rewiring banks’ cyber defence from reactive to preemptive in 2026
  • PodChats for FutureCISO: What needs to happen for AI to deliver on its promises in 2026
  • AI security fabric is a step towards safe AI implementation
  • Over 90% of CISOs emphasise importance of OT/IT security convergence

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
  • Events
Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl