Also known as: APT34, Earth Preta, Stately Taurus, tracked as, Midnight Blizzard has, conference Wi-Fi portals worldwide, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, APT28, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, Earth Lusca, TAG-22, Aquatic Panda, Red Dev 10, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, Evasive Panda
LongNosedGoblin is a well‑coordinated threat actor that operates with the strategic objectives of gaining persistent access to high‑value targets in government and defense sectors across Southeast Asia and Japan. The group tailors its toolset around .NET frameworks, featuring custom loaders like NosyHistorian and shared malware families such as NosyDoor, which facilitate data collection, stealthy persistence, and lateral movement. In deployment, the actor exploits trusted enterprise mechanisms—most notably Group Policy—to sidestep perimeter defenses and spread laterally within compromised networks. It circumvents script‑scanning engines like AMSI and leverages living‑off‑the‑land capabilities including AppDomainManager injection to execute malicious payloads in memory. Command-and-control is largely conducted through legitimate cloud storage services (OneDrive, Yandex Disk) that provide a hardened tunneling environment. LongNosedGoblin’s operational footprint includes advanced exfiltration strategies: data collection spans browser histories, system configuration, and even video capture using FFmpeg, after which files are staged locally then transferred via public cloud or file‑sharing services. The actor demonstrates an aptitude for zero‑day exploitation—most recently the Cityworks CVE‑2025‑0994 vulnerability—to augment its compromise vectors. Overall, LongNosedGoblin exemplifies a sophisticated, multi‑stage adversary that blends native functionality with custom backdoors to achieve long‑term espionage objectives across targeted jurisdictions.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
LongNosedGoblin is a China‑aligned advanced persistent threat group focused on cyberespionage against governmental, defense, and critical infrastructure entities in Southeast Asia and Japan. Leveraging living‑off‑the‑land techniques, the actor deploys .NET malware via Group Policy, uses cloud services such as OneDrive and Yandex Disk for command‑and‑control, and exfiltrates data through public file‑sharing platforms. The group’s operations are sophisticated, exploiting zero‑day vulnerabilities like Cityworks CVE‑2025‑0994 to establish further footholds.
Goals & Targeting
The organization’s primary aim is strategic intelligence collection against state actors and critical infrastructure operators in their target regions. By exploiting trusted systems, the group seeks persistent network access which enables ongoing monitoring, data harvesting (including operational documents, browser histories, and recorded conversations), and credential theft for broader lateral movement or future campaign phases. The focus on diplomatic officials and defense entities signals a deliberate effort to infiltrate decision‑making environments and obtain sensitive information that can influence geopolitical dynamics.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
LongNosedGoblin conducts operations at an intermediate tempo, targeting governmental entities with high-value intelligence assets in Southeast Asia and Japan. Victim networks typically include defense ministries, telecommunications providers, and diplomatic missions where credentials and privileged information are abundant. The actor often deploys its .NET backdoors across multiple subnets using Group Policy or native tools, following up with lateral movement facilitated by AppDomainManager injection. Exfiltration tends to leverage public cloud services (OneDrive, Yandex Disk) rather than custom exfil channels, allowing detection only through traffic anomaly analysis. Notable attacks include the Cityworks CVE‑2025‑0994 zero‑day exploit used to bootstrap a VSHELL stager, and documented use of NosyDoor for espionage against Kurdish diplomatic officials.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based primarily on publicly released analyst reports and observed tool usage. While the core behaviors—Group Policy deployment, cloud‑based C2, .NET backdoors, and known asset exploitation—are well documented, attribution depth remains moderate due to limited internal indicator confirmation and potential overlap with related APT families (e.g., OilRig/APT34). Unknowns persist around the full geographic reach of the actor, exact operational tempo, and long‑term persistence mechanisms. Continuous monitoring and shared indicators are recommended to refine confidence over time.
Satellite Turla
Epic Turla
The 'Penquin' Turla
Witchcoven
RUAG hack
Mosquito
Moonlight Maze
No observed data linked yet.
37
Techniques
64
Tools
7
Campaigns
40
IOCs
0
Observed Data
10
Tactics